{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/websphere-application-server-8.5-9.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-10842"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WebSphere Application Server (8.5, 9.0)","WebSphere Application Server - Liberty (17.0.0.3 - 26.0.0.7)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM has disclosed a security vulnerability, CVE-2026-10842, identified as an authentication bypass via alternate name (CWE-289). This vulnerability affects IBM WebSphere Application Server versions 8.5 and 9.0, as well as IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.7. The flaw permits a remote, unauthenticated attacker to bypass established security constraints, potentially leading to unauthorized access to sensitive application resources or administrative functions. Given the base CVSS score of 7.5, this vulnerability represents a significant risk to enterprise environments where WebSphere serves as a critical middleware component. Defenders should prioritize patching affected instances and monitoring for unusual traffic patterns targeting authentication-related endpoints or administrative interfaces.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-10842 allows for complete bypass of security controls enforced by the affected WebSphere instances. This could lead to unauthorized data access, potential compromise of internal business logic, or exposure of administrative interfaces to unauthenticated remote actors. The vulnerability impacts widespread enterprise deployments of WebSphere, posing a risk of data exfiltration and loss of integrity for business-critical applications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the application of vendor-supplied patches as detailed in the IBM security bulletin.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security patches or upgrade to the non-vulnerable versions specified in the IBM support document provided in the references.\u003c/li\u003e\n\u003cli\u003eReview access logs for web applications hosted on affected WebSphere instances to identify spikes in 401 or 403 status codes followed by successful access to sensitive resources.\u003c/li\u003e\n\u003cli\u003eAudit administrative and application-level access controls to identify any bypassed security constraints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T17:30:18Z","date_published":"2026-07-30T17:29:55Z","id":"https://feed.craftedsignal.io/briefs/2026-07-websphere-auth-bypass/","summary":"A critical authentication bypass vulnerability (CVE-2026-10842) allows remote, unauthenticated attackers to circumvent security constraints in IBM WebSphere Application Server and Liberty versions.","title":"Authentication Bypass Vulnerability in IBM WebSphere Application Server","url":"https://feed.craftedsignal.io/briefs/2026-07-websphere-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - WebSphere Application Server (8.5, 9.0)","version":"https://jsonfeed.org/version/1.1"}