← Back to CVE search

CVE-2026-3621

IBM WebSphere Application Server Liberty

Description

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.

CVSS 7.5EPSS 0.27599999999999997%Risk 0.77
View source
Published
2026-04-23 00:16:45
Affected versions
>=17.0.0.3,<26.0.0.5
Type
Core software
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H