Authentication Bypass by Alternate Name in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - CVE-2026-10842

 

Authentication Bypass by Alternate Name in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - CVE-2026-10842

Published: July 17, 2026


Vulnerability identifier: #VU138311
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-10842
CWE-ID: CWE-289
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security constraints.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker can bypass security constraints and gain unauthorized access to the application.


Affected software

IBM WebSphere Application Server
IBM WebSphere Application Server Liberty
Enterprise Application Runtimes
WebSphere Hybrid Edition
Cloud Pak for Applications
Jazz for Service Management
IBM Rational ClearQuest
IBM Watson Explorer Analytical Components
IBM Watson Explorer Foundational Components

How to mitigate CVE-2026-10842

Install updates from vendor's website.

IBM WebSphere Application Server - addressed in versions 8.5.5.30, 9.0.5.29
IBM WebSphere Application Server Liberty - update to 26.0.0.8
IBM Watson Explorer Analytical Components - update to 12.0.3.22 PH71916
IBM Watson Explorer Foundational Components - update to 12.0.3.22 PH71916

External References

Related Security Bulletins