CVE-2026-3621

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.
References
Link Resource
https://www.ibm.com/support/pages/node/7270437 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:*

History

13 May 2026, 20:24

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:*
CWE NVD-CWE-noinfo
References () https://www.ibm.com/support/pages/node/7270437 - () https://www.ibm.com/support/pages/node/7270437 - Vendor Advisory
First Time Ibm
Ibm websphere Application Server

23 Apr 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-23 00:16

Updated : 2026-05-13 20:24


NVD link : CVE-2026-3621

Mitre link : CVE-2026-3621

CVE.ORG link : CVE-2026-3621


JSON object : View

Products Affected

ibm

  • websphere_application_server
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo