
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-16189 is a log injection vulnerability in IBM WebSphere Application Server (WAS) that allows a remote attacker to inject forged entries into the server's administrative log. It affects IBM WebSphere Application Server versions 8.5 and 9.0. The vulnerability was published on September 14, 2026, and carries a CVSS v3.1 base score of 4.8 (Medium) (IBM Advisory, ENISA EUVD).
The root cause is classified as CWE-117 (Improper Output Neutralization for Logs), meaning user-supplied input is not properly sanitized before being written to the administrative log. An attacker can craft malicious HTTP requests containing newline characters or other control sequences that, when logged, introduce forged log entries. Exploitation requires high attack complexity (AC:H) but no authentication or user interaction, and is performed over the network. This maps to CAPEC-93 (Log Injection-Tampering-Forging) and CAPEC-268 (Audit Log Manipulation) (IBM Advisory, Feedly).
Successful exploitation allows a remote attacker to corrupt the integrity of the administrative log by inserting fabricated entries, potentially obscuring malicious activity or framing legitimate users. The vulnerability has a low confidentiality impact (log content may be partially influenced or revealed) and a low integrity impact (log tampering), with no availability impact. This can hinder incident response and forensic investigations by undermining the trustworthiness of audit trails (IBM Advisory).
As of the publication date, there are no known public proof-of-concept exploits, no reported in-the-wild exploitation, and no CISA KEV catalog listing for this CVE. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The high attack complexity requirement further reduces the likelihood of opportunistic exploitation (ENISA EUVD).
%0a, carriage return %0d) embedded in user-controlled input fields (such as HTTP headers, URL parameters, or form fields) that are reflected into the administrative log.%0a) or carriage return (%0d) characters in headers, query parameters, or POST body fields.IBM has published a security bulletin (IBM Support Page 7286610) addressing this vulnerability; administrators should consult the advisory for specific fix pack versions applicable to WAS 8.5 and 9.0. As a general workaround, restrict network access to the WAS administrative console to trusted IP ranges and implement a web application firewall (WAF) rule to block requests containing log injection characters. Upgrading to the patched fix pack level specified in the IBM advisory is the recommended remediation (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."