<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>WebSphere Application Server - Liberty (17.0.0.3 - 26.0.0.7) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/websphere-application-server---liberty-17.0.0.3---26.0.0.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 30 Jul 2026 17:29:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/websphere-application-server---liberty-17.0.0.3---26.0.0.7/feed.xml" rel="self" type="application/rss+xml"/><item><title>Authentication Bypass Vulnerability in IBM WebSphere Application Server</title><link>https://feed.craftedsignal.io/briefs/2026-07-websphere-auth-bypass/</link><pubDate>Thu, 30 Jul 2026 17:29:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-websphere-auth-bypass/</guid><description>A critical authentication bypass vulnerability (CVE-2026-10842) allows remote, unauthenticated attackers to circumvent security constraints in IBM WebSphere Application Server and Liberty versions.</description><content:encoded><![CDATA[<p>IBM has disclosed a security vulnerability, CVE-2026-10842, identified as an authentication bypass via alternate name (CWE-289). This vulnerability affects IBM WebSphere Application Server versions 8.5 and 9.0, as well as IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.7. The flaw permits a remote, unauthenticated attacker to bypass established security constraints, potentially leading to unauthorized access to sensitive application resources or administrative functions. Given the base CVSS score of 7.5, this vulnerability represents a significant risk to enterprise environments where WebSphere serves as a critical middleware component. Defenders should prioritize patching affected instances and monitoring for unusual traffic patterns targeting authentication-related endpoints or administrative interfaces.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-10842 allows for complete bypass of security controls enforced by the affected WebSphere instances. This could lead to unauthorized data access, potential compromise of internal business logic, or exposure of administrative interfaces to unauthenticated remote actors. The vulnerability impacts widespread enterprise deployments of WebSphere, posing a risk of data exfiltration and loss of integrity for business-critical applications.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the application of vendor-supplied patches as detailed in the IBM security bulletin.</p>
<ul>
<li>Apply the security patches or upgrade to the non-vulnerable versions specified in the IBM support document provided in the references.</li>
<li>Review access logs for web applications hosted on affected WebSphere instances to identify spikes in 401 or 403 status codes followed by successful access to sensitive resources.</li>
<li>Audit administrative and application-level access controls to identify any bypassed security constraints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>