PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-4410 IBM CVE debrief

IBM WebSphere Application Server Liberty versions 19.0.0.7 through 26.0.0.5, along with WebSphere Application Server 9.0 and 8.5, contain a denial-of-service vulnerability. A remote attacker can exploit this flaw by sending a specially crafted request, causing the server to consume excessive memory resources. The CVSS 3.1 vector (AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates this requires adjacent network access, high attack complexity, and low privileges, with no impact to confidentiality or integrity but high availability impact. IBM has published remediation guidance.

Vendor
IBM
Product
WebSphere Application Server - Liberty
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-27
Original CVE updated
2026-06-01
Advisory published
2026-05-27
Advisory updated
2026-06-01

Who should care

Organizations running IBM WebSphere Application Server Liberty versions 19.0.0.7 through 26.0.0.5, or WebSphere Application Server 9.0/8.5, particularly those with exposed management interfaces or limited network segmentation. Infrastructure teams responsible for Java application server security and availability should prioritize patching.

Technical summary

The vulnerability stems from improper handling of specially crafted requests leading to uncontrolled memory consumption (CWE-400). Affected components include IBM WebSphere Application Server Liberty (19.0.0.7-26.0.0.5), WebSphere Application Server 9.0, and 8.5. The attack requires adjacent network access and low privileges but high attack complexity, resulting in high availability impact through memory resource exhaustion. No confidentiality or integrity impacts are associated with this vulnerability.

Defensive priority

medium

Recommended defensive actions

  • Apply IBM-provided security updates for affected WebSphere Application Server versions per vendor guidance
  • Review network segmentation to limit adjacent network access to WebSphere management interfaces
  • Monitor server memory utilization for anomalous consumption patterns
  • Validate that WebSphere deployments run supported versions (Liberty 26.0.0.6 or later, or vendor-specified fixes)
  • Assess exposure of WebSphere administrative interfaces and restrict access to authorized hosts only

Evidence notes

The vulnerability affects multiple IBM WebSphere Application Server versions including Liberty 19.0.0.7-26.0.0.5, WAS 9.0, and WAS 8.5. The attack vector requires adjacent network access with high complexity, limiting widespread exploitation. No evidence of known ransomware campaign use or CISA KEV inclusion as of the source publication date.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-4410 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-4410

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-4410 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4410

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.