
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11540 is an information disclosure vulnerability in IBM WebSphere Application Server (WAS) versions 9.0 and 8.5, caused by incorrect authorization in the FileTransfer servlet. It allows unauthenticated remote attackers to obtain sensitive information about the server's file system. The vulnerability was published on September 18, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, IBM Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization), meaning the FileTransfer servlet does not correctly enforce authorization checks when actors attempt to access file system resources. An unauthenticated remote attacker can send network requests to the FileTransfer servlet endpoint without supplying valid credentials, bypassing access controls and receiving sensitive file system information in the response. The attack requires no user interaction, no special privileges, and low complexity, making it straightforward to automate (Github Advisory, IBM Advisory).
Successful exploitation results in partial confidentiality loss — specifically, an unauthenticated attacker can retrieve sensitive information about the file system structure of the affected WebSphere Application Server instance. There is no impact to integrity or availability. While the direct impact is limited to information disclosure, exposed file system details (e.g., directory paths, file names) could assist attackers in planning further targeted attacks against the server (Github Advisory).
There is currently no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.302% (21st percentile), indicating a low near-term probability of exploitation. NVD SSVC assessment notes the vulnerability is automatable with partial technical impact and no known exploitation (Feedly).
/FileTransfer or similar WAS servlet paths)./FileTransfer) from external or unknown IP addresses.IBM has released a security patch for WebSphere Application Server versions 8.5 and 9.0, available via the IBM support page (node 7286610). Organizations should apply the patch as the primary remediation step. As interim workarounds, restrict network access to the FileTransfer servlet using firewall rules or a Web Application Firewall (WAF), and consider disabling the FileTransfer servlet entirely if it is not required for operations (IBM Advisory, Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."