CVE-2026-3621

HIGH

IBM WebSphere Application Server Liberty is affected by identity spoofing

Title source: cna
STIX 2.1

Description

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.

Scores

CVSS v3 7.5
EPSS 0.0005
EPSS Percentile 15.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
IBM/WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.4
Published Apr 23, 2026
Tracked Since Apr 23, 2026