CVE-2026-3621

· NIST NVD ↗

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.

HIGH
CVSS severity
7.5
CVSS base score
2026-04-23
Published

CWE codes

CWE-269NVD-CWE-noinfo

Affected products

ibm:websphere_application_server

Sources