CVE-2026-3621

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.
References
Link Resource
https://www.ibm.com/support/pages/node/7270437 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:*

History

No history.

Information

Published : 2026-04-23 00:16

Updated : 2026-06-17 10:43


NVD link : CVE-2026-3621

Mitre link : CVE-2026-3621

CVE.ORG link : CVE-2026-3621


JSON object : View

Products Affected

ibm

  • websphere_application_server
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo