
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-10842 is a security constraint bypass vulnerability affecting IBM WebSphere Application Server (WAS) and IBM WebSphere Application Server Liberty. It allows a remote, unauthenticated attacker to bypass security constraints and potentially access protected resources. Affected products include IBM WebSphere Application Server versions 8.5 (before 8.5.5.31) and 9.0 (before 9.0.5.29), and IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.7. The vulnerability was published on July 30, 2026, with patches made available around the same time. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, IBM Advisory).
The vulnerability is classified as CWE-289 (Authentication Bypass by Alternate Name), meaning the product performs authentication or access control decisions based on the name of a resource or actor without properly checking all possible names or aliases for that resource (GitHub Advisory). An attacker can exploit this by crafting requests that reference a resource using an alternate name or path that bypasses the configured security constraints. No authentication, user interaction, or elevated privileges are required, and the attack can be performed entirely over the network with low complexity. No public proof-of-concept exploit code has been identified at this time (Feedly).
Successful exploitation allows an unauthenticated remote attacker to bypass security constraints and gain unauthorized access to protected resources or functionality within the affected WebSphere Application Server instances. The primary impact is a high confidentiality loss — sensitive data or restricted application functionality may be exposed to unauthorized parties. Integrity and availability are not directly impacted by this vulnerability. The broad deployment of IBM WebSphere in enterprise environments means that exploitation could expose sensitive business data, internal APIs, or administrative interfaces (GitHub Advisory, IBM Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of this report (Feedly). The vulnerability is rated automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction. The EPSS score is approximately 0.33%, placing it in the 24th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
IBM has released patched versions to address this vulnerability. Users should upgrade to the following fixed versions: IBM WebSphere Application Server 8.5.5.31 or later, IBM WebSphere Application Server 9.0.5.29 or later, and IBM WebSphere Application Server Liberty 26.0.0.8 or later (IBM Advisory, Open Liberty Blog). Organizations using IBM products that bundle WAS — such as IBM Cloud Pak for Applications, IBM Business Automation Workflow, and IBM Jazz Service Management — should consult the respective IBM security bulletins for guidance on applying fixes to those bundled components. Upgrading to a patched version is the recommended remediation; no specific configuration-based workaround has been publicly documented.
IBM published multiple security bulletins addressing CVE-2026-10842 across its product portfolio, including advisories for Jazz Service Management, IBM Cloud Pak for Applications, and IBM Business Automation Workflow (IBM JazzSM Bulletin, IBM Cloud Pak Bulletin). HCL Software also published a community blog post referencing the vulnerability in the context of products that bundle IBM WebSphere (HCL Blog). No significant independent researcher commentary or broad social media discussion has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."