CVE-2026-8644
published 2026-06-01CVE-2026-8644: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
PriorityP346critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.33%
25.5th percentile
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bagisto | bagisto | >= 0 < 2.3.10 | 2.3.10 |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | >= 8.5.0.0 < 8.5.5.30 | 8.5.5.30 |
| ibm | websphere_application_server | 9.0 – 1.1.9.12 | — |
| ibm | websphere_application_server | >= 9.0.0.0 < 9.0.5.29 | 9.0.5.29 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
ghsa_unreviewed·2026-06-01
CVE-2026-8644 [CRITICAL] CWE-290 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
VulDB
IBM WebSphere Application Server 8.5/9.0 authentication spoofing
vuldb·2026-06-01·CVSS 9.1
CVE-2026-8644 [CRITICAL] IBM WebSphere Application Server 8.5/9.0 authentication spoofing
A vulnerability was found in IBM WebSphere Application Server 8.5/9.0. It has been rated as critical. This impacts an unknown function. This manipulation causes authentication bypass by spoofing.
This vulnerability is tracked as CVE-2026-8644. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
Bagisto has Normal & Blind SSTI from low-privilege user when ordering product
ghsa·2026-01-02
CVE-2026-21448 [HIGH] CWE-1336 Bagisto has Normal & Blind SSTI from low-privilege user when ordering product
Bagisto has Normal & Blind SSTI from low-privilege user when ordering product
### Summary
SSTI when normal customer orders any product in add address step can inject value run in admin view.
### Details
`As normal user`
1. Go to `http://127.0.0.1:8000/`
2. Add order to cart and continue to checkout
3. In step of add address inject this value {{7*7}} in any input
`As admin`
1. Go to `http://127.0.0.1:8000/admin/sales/orders`
2. And notice the vlaue appear in admin view 49
`As normal user`
3. Go to add address normally `http://127.0.0.1:8000/customer/account/addresses/create` and inject {{7*7}} on it and will notice it appear 49
### PoC
- Video attached with the report: https://github.com/user-attachments/assets/a814b30c-a3e2-4a40-8644-336e21e60d0d
### Impact
- Can lead to RCE
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-01
Published