CVE-2026-8646
published 2026-06-22CVE-2026-8646: IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling…
PriorityP352critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.34%
25.8th percentile
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | >= 17.0.0.3 < 26.0.0.7 | 26.0.0.7 |
| ibm | websphere_application_server | 8.5.0 – 7.0.3 Interim Fix 017 | — |
| ibm | websphere_application_server | >= 8.5.0.0 < 8.5.5.30 | 8.5.5.30 |
| ibm | websphere_application_server | 9.0.0 – 7.0.2 Interim Fix 035 | — |
| ibm | websphere_application_server | >= 9.0.0.0 < 9.0.5.29 | 9.0.5.29 |
| ibm | websphere_application_server_liberty | 17.0.0.3 – 26.0.0.6 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling.
ghsa_unreviewed·2026-06-22
CVE-2026-8646 [HIGH] CWE-444 IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling.
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.
VulDB
IBM WebSphere Application Server up to 8.5/9.0/17.0.0.3/26.0.0.6 request smuggling
vuldb·2026-06-22·CVSS 7.4
CVE-2026-8646 [HIGH] IBM WebSphere Application Server up to 8.5/9.0/17.0.0.3/26.0.0.6 request smuggling
A vulnerability was found in IBM WebSphere Application Server up to 8.5/9.0/17.0.0.3/26.0.0.6 and classified as problematic. Affected is an unknown function. Executing a manipulation can lead to http request smuggling.
This vulnerability is tracked as CVE-2026-8646. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-22
Published