
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11545 is a missing authorization vulnerability in IBM WebSphere Application Server (WAS) that allows a remote attacker to obtain sensitive information from the administrative console. It affects IBM WebSphere Application Server versions 8.5 and 9.0. The vulnerability was published on September 18, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 3.7 (Low) (GitHub Advisory, IBM Support).
The root cause is classified as CWE-862 (Missing Authorization): the administrative console in IBM WebSphere Application Server 8.5 and 9.0 fails to perform proper authorization checks when an actor attempts to access certain resources or perform specific actions. This allows a network-based, unauthenticated attacker to query or view sensitive information exposed through the console interface. Exploitation requires high attack complexity, meaning specific conditions or timing must be met, which limits the ease of exploitation. No public proof-of-concept code or detailed technical write-up has been identified (GitHub Advisory, IBM Support).
Successful exploitation results in unauthorized disclosure of sensitive information accessible via the IBM WebSphere Application Server administrative console, with no impact to integrity or availability. The confidentiality impact is rated Low, meaning only partial or limited information is exposed rather than full system compromise. The vulnerability does not provide a direct path to code execution or lateral movement, but exposed administrative console data could potentially aid further targeted attacks against the environment (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2026-11545 (GitHub Advisory). The EPSS score is approximately 0.34% (16th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. The high attack complexity requirement further reduces the practical exploitability of this vulnerability.
IBM has released a patch for WebSphere Application Server 8.5 and 9.0, detailed in the IBM support bulletin at node 7286730. Organizations should apply the available fix promptly. As an interim workaround, restrict network access to the WAS administrative console to trusted internal networks only, and implement network-level controls (e.g., firewall rules, VPN requirements) to limit exposure of the console interface to untrusted parties (IBM Support, GitHub Advisory).
Coverage of CVE-2026-11545 has been limited to automated vulnerability tracking platforms such as VulDB and Offseq Radar, with no notable researcher commentary or significant community discussion identified. IBM published the security bulletin and patch on September 18, 2026, without additional public statements beyond the standard advisory (IBM Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."