CVE-2026-11708
Critical · CVSS 9.3IBM WebSphere Application Server — Cross-Site Scripting (XSS)
- CVSS
- 9.3
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-79
Description
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
Search profile — drives PoC discovery
Symbols administrative consoleintegrated help systemWebSphere admin console XSShelp system endpoint
Keywords CVE-2026-11708IBM WebSphere Application Server XSSWebSphere administrative console cross-site scriptingWebSphere help system XSSIBM WebSphere 9.0 8.5 XSSCWE-79 WebSphere
Versions: 8.5, 9.0
References
Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z