Improper privilege management in IBM WebSphere Application Server Liberty - CVE-2026-3621
Published: June 24, 2026
Vulnerability identifier: #VU135090
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-3621
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability occurs when an application is deployed without authentication and authorization configured. A remote user can escalate privileges.
Affected software
IBM WebSphere Application Server Liberty
IBM Cloud Transformation Advisor
IBM MQ Operator
IBM Tivoli Monitoring
IBM SPSS Collaboration and Deployment Services
PowerVM NovaLink
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
IBM OpenPages with Watson
IBM supplied MQ Advanced container images
Application Modernization Accelerator
Data Product Hub
Storage Protect Operations Center
IBM InfoSphere Information Server
IBM Cloud Transformation Advisor
IBM MQ Operator
IBM Tivoli Monitoring
IBM SPSS Collaboration and Deployment Services
PowerVM NovaLink
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
IBM OpenPages with Watson
IBM supplied MQ Advanced container images
Application Modernization Accelerator
Data Product Hub
Storage Protect Operations Center
IBM InfoSphere Information Server
How to mitigate CVE-2026-3621
Install updates from vendor's website.
IBM Cloud Transformation Advisor - update to 5.0.0
PowerVM NovaLink - addressed in versions 2.2.1.1, 2.3.3
IBM MQ Operator - addressed in versions 3.2.26 SC2, 4.0.1 SC2
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 22
Storage Protect Client - update to 8.2.2.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.2.0
Storage Protect for Space Management - update to 8.2.2.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.2.0
IBM supplied MQ Advanced container images - update to 10.0.0.0-r2
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
Application Modernization Accelerator - update to 5.0.0
Data Product Hub - addressed in versions 5.3.1 Patch 7, 5.4.0
Storage Protect Operations Center - update to 8.2.2
PowerVM NovaLink - addressed in versions 2.2.1.1, 2.3.3
IBM MQ Operator - addressed in versions 3.2.26 SC2, 4.0.1 SC2
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 22
Storage Protect Client - update to 8.2.2.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.2.0
Storage Protect for Space Management - update to 8.2.2.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.2.0
IBM supplied MQ Advanced container images - update to 10.0.0.0-r2
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
Application Modernization Accelerator - update to 5.0.0
Data Product Hub - addressed in versions 5.3.1 Patch 7, 5.4.0
Storage Protect Operations Center - update to 8.2.2
External References
Related Security Bulletins
- Improper privilege management in IBM WebSphere Application Server - Liberty
- Multiple vulnerabilities in IBM Data Product Hub
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in IBM PowerVM Novalink
- Multiple vulnerabilities in IBM Application Modernization Accelerator
- Multiple vulnerabilities in IBM Transformation Advisor
- Multiple vulnerabilities in IBM OpenPages
- Improper privilege management in IBM Storage Protect Client and Virtual Environments
- Improper privilege management in IBM Storage Protect for Space Management
- Improper privilege management in IBM Storage Protect Operations Center
- Multiple vulnerabilities in IBM Tivoli Monitoring