CVE-2026-9327
published 2026-09-10CVE-2026-9327: IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This…
PriorityP343high8.1CVSS 3.1
AVNACLPRLUINSUCHINAH
EPSS
0.21%
11.8th percentile
IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | >= 8.5.0.0 < 8.5.5.31 | 8.5.5.31 |
| ibm | websphere_application_server | >= 9.0.0.0 < 9.0.5.29 | 9.0.5.29 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM WebSphere Application Server 8.5/9.0 privileges management
vuldb·2026-09-10·CVSS 6.3
CVE-2026-9327 [MEDIUM] IBM WebSphere Application Server 8.5/9.0 privileges management
A vulnerability, which was classified as critical, was found in IBM WebSphere Application Server 8.5/9.0. The impacted element is an unknown function. The manipulation results in improper privilege management.
This vulnerability is reported as CVE-2026-9327. The attack can be launched remotely. No exploit exists.
GHSA
IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration.
ghsa_unreviewed·2026-09-10
CVE-2026-9327 [MEDIUM] CWE-269 IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration.
IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-10
Published