CVE-2026-3621
HIGHIBM WebSphere Application Server Liberty is affected by identity spoofing
Title source: cnaDescription
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.
Scores
CVSS v3
7.5
EPSS
0.0005
EPSS Percentile
15.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (1)
IBM/WebSphere Application Server - Liberty
17.0.0.3 - 26.0.0.4
Published
Apr 23, 2026
Tracked Since
Apr 23, 2026