CVE-2026-8644 Details
Description
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
An identity spoofing vulnerability has been identified in IBM WebSphere Application Server versions 9.0 and 8.5. This vulnerability allows for authentication bypass by spoofing, potentially leading to unauthorized actions or access.
Users are advised to upgrade to the latest fix pack or apply the available interim fix for APAR PH71422. For WebSphere Application Server 9.0.0.0 through 9.0.5.28, upgrade to the required minimal fix pack level and then apply the interim fix. Alternatively, users can apply Fix Pack 9.0.5.29 or later, with 9.0.5.30 targeted for availability in 3Q2026. For WebSphere Application Server 8.5.0.0 through 8.5.5.29, the same upgrade and interim fix application process applies, or users can upgrade to Fix Pack 8.5.5.30 or later, also targeted for 3Q2026.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7274740 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm websphere application server | >= 8.5.0.0, < 8.5.5.30 >= 9.0.0.0, < 9.0.5.29 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | New CVE Received | [email protected] |