PatchSiren cyber security CVE debrief
CVE-2026-8835 IBM CVE debrief
IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain an invalid pointer dereference vulnerability in the Administration Server component. An authenticated privileged user can trigger this flaw to read sensitive information or cause denial of service. The vulnerability requires adjacent network access and low attack complexity, with confidentiality and availability impacts rated HIGH. IBM has released security updates addressing this issue.
- Vendor
- IBM
- Product
- HTTP Server
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-07-23
Who should care
Organizations running IBM HTTP Server 8.5 or 9.0 with Administration Server enabled; security teams managing WebSphere Application Server infrastructure; compliance officers tracking patch status for HIGH severity vulnerabilities
Technical summary
The vulnerability exists in IBM HTTP Server's Administration Server component where improper pointer handling allows an authenticated privileged user to dereference invalid memory. The attack vector requires adjacent network access (AV:A) and valid privileged credentials (PR:L), with no user interaction required. Successful exploitation can expose sensitive memory contents (C:H) or crash the server process (A:H). The flaw does not impact integrity (I:N). Affected platforms include AIX, z/OS, Linux, and Windows deployments running vulnerable IBM HTTP Server versions.
Defensive priority
HIGH
Recommended defensive actions
- Apply IBM HTTP Server fix packs 8.5.5.30 or 9.0.5.29 or later per vendor security advisory
- Restrict Administration Server network access to trusted administrative hosts only
- Audit privileged accounts with Administration Server access for unauthorized activity
- Monitor Administration Server logs for anomalous requests or unexpected process terminations
- Validate pointer safety controls in custom modules interacting with Administration Server APIs
Evidence notes
Vulnerability confirmed via NVD CPE criteria showing affected versions 8.5.0.0 through 8.5.5.30 (exclusive) and 9.0.0.0 through 9.0.5.29 (exclusive). CVSS 3.1 vector AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H supports adjacent network, low complexity, privileged access requirements. CWE-822 (Untrusted Pointer Dereference) classified as primary weakness. IBM PSIRT advisory published 2026-05-26.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8835 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8835
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8835 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8835
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7274065
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.