SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-9176

MEDIUM · CVSS 6.7 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

IBM WebSphere Application Server versions 9.0 and 8.5 are susceptible to a security bypass stemming from inadequate authentication controls, allowing local attackers to escalate privileges. This vulnerability could enable unauthorized access to sensitive resources, posing a risk to the integrity of applications running on these servers. Organizations using these versions should prioritize remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-9176
Severity
MEDIUM
CVSS
6.7
EPSS
0.13%

Original NVD Description

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.