SEPTEMBER 24, 2026
Live Feed
Back to database
Case File

CVE-2026-11538

LOW · CVSS 3.7 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-09-24

CyberRota Analysis

AI-Generated

IBM WebSphere Application Server versions 9.0 and 8.5 are vulnerable to a log injection attack via specially crafted LTPA token cookies, which could allow an attacker to manipulate log files and potentially disclose sensitive information. While the severity is rated low, organizations using these versions should prioritize remediation to mitigate any risk of information leakage and maintain the integrity of their logging mechanisms. This is particularly relevant for security teams and system administrators managing WebSphere environments.

CVE
CVE-2026-11538
Severity
LOW
CVSS
3.7
EPSS
0.16%

Original NVD Description

IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.

Related CVEs

Other vulnerabilities affecting the same vendor(s)