CVE-2026-16188
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-117
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- IBM WebSphere Application Server
- IBM WebSphere Application Server
Weakness type
Related vulnerabilities
- CVE-2026-25548 — InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning
- CVE-2024-47083 — Power Platform Terraform Provider has Improper Masking of Secrets in Logs
- CVE-2024-29022 — Session Hijacking via XSS attack in header and session grid in Xibo CMS
- CVE-2023-32712 — Unauthenticated Log Injection in Splunk Enterprise
- CVE-2024-25047 — IBM Cognos Analytics log injection
- CVE-2023-4571 — Unauthenticated Log Injection in Splunk IT Service Intelligence (ITSI)
- CVE-2023-3997 — Unauthenticated Log Injection In Splunk SOAR
- CVE-2026-62948 — OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI