Description
IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.
Published: 2026-05-27
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH70798. To determine if a feature is enabled for IBM WebSphere Application Server Liberty, refer to How to determine if Liberty is using a specific feature https://www.ibm.com/support/pages/node/6553910 .  For IBM WebSphere Application Server Liberty 22.0.0.11 - 26.0.0.5 using the appSecurity-3.0, appSecurity-4.0 or appSecurity-5.0 feature(s):  · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH70798 https://www.ibm.com/support/pages/node/7273239 --OR-- · Apply Liberty Fix Pack 26.0.0.6 or later (targeted availability 3Q2026).  Additional interim fixes may be available and linked off the interim fix download page.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Ibm websphere Application Server
CPEs cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:*
Vendors & Products Ibm websphere Application Server

Wed, 27 May 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 27 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.
Title IBM WebSphere Application Server Liberty is affected by a security bypass vulnerability
First Time appeared Ibm
Ibm websphere Application Server Liberty
CPEs cpe:2.3:a:ibm:websphere_application_server___liberty:22.0.0.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server___liberty:26.0.0.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server Liberty
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Websphere Application Server Websphere Application Server Liberty
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-06-02T16:13:02.756Z

Reserved: 2026-04-03T21:59:13.972Z

Link: CVE-2026-5516

cve-icon Vulnrichment

Updated: 2026-05-27T14:43:46.126Z

cve-icon NVD

Status : Modified

Published: 2026-05-27T14:17:34.257

Modified: 2026-06-17T10:59:09.287

Link: CVE-2026-5516

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T01:15:03Z

Weaknesses