CVE Vulnerabilities

CVE-2026-10845

Improper Authentication

Published: Jun 22, 2026 | Modified: Jun 23, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Websphere_application_serverIbm8.5.0.0 (including)8.5.5.30 (excluding)
Websphere_application_serverIbm9.0.0.0 (including)9.0.5.29 (excluding)

Potential Mitigations

References