Record summary

CVE-2026-10842 has a selected CVSS score of 7.5 (high).

Description

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 30, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

WebSphere Application Server

Browse IBM / WebSphere Application Server
CVE List8.5affected
9.0affected

WebSphere Application Server - Liberty

Browse IBM / WebSphere Application Server - Liberty
CVE List17.0.0.3 to ≤ 26.0.0.7affected

References

2