# IBM WebSphere Application Server & Liberty Web Server Plug-ins Unauthenticated RCE and HTTP Request Smuggling (CVE-2026-8633, CVE-2026-8620)

> IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5 and 9.0 contain a critical unauthenticated remote code execution flaw (CVE-2026-8633, CWE-94, CVSS 9.8) reachable via a specially crafted HTTP request, alongside a high-severity HTTP request smuggling flaw (CVE-2026-8620, CWE-444, CVSS 7.5) in the same native plug-in. Because the plug-in is a native module loaded directly into the front-end web server (IBM HTTP Server / Apache / IIS), successful exploitation yields code execution in the internet-facing web tier with no authentication or user interaction.

- **Published:** 2026-06-01T00:00:00Z
- **Last reviewed:** 2026-06-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0650
- **ID:** TL-2026-0650
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-8633, CVE-2026-8620

## Description

IBM disclosed two vulnerabilities on 26 May 2026 affecting the Web Server Plug-ins component shipped with IBM WebSphere Application Server (traditional) and WebSphere Application Server Liberty, versions 8.5 and 9.0 (IBM Security Bulletin, node 7274072; tracked under APAR PH71342).

The Web Server Plug-ins are not part of the application server JVM. They are native modules (for example was_ap24_module / mod_was_ap24_http.so for Apache 2.4-based IBM HTTP Server 9.0, was_ap22_module / mod_was_ap22_http.so for Apache 2.2, plus ISAPI/NSAPI variants) that are loaded via a LoadModule directive directly into the front-end web server worker process. The plug-in reads plugin-cfg.xml, parses inbound HTTP requests, applies routing/affinity rules, and forwards matched traffic to back-end WebSphere application servers over the WCInbound transport (HTTP or HTTPS, the latter secured with the bundled GSKit SSL library). Because the plug-in runs in-process inside the web server, any memory-safety or code-generation defect in its request-parsing path executes with the privileges of the web server process — typically a low-privileged service account (apache/nobody/www on Unix, the IHS service account on Windows), but on the internet-facing edge of the environment.

CVE-2026-8633 (CVSS 3.1 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) is classified CWE-94, Improper Control of Generation of Code (Code Injection). Per NVD and IBM, an unauthenticated remote attacker can trigger arbitrary code execution in the Web Server Plug-ins by sending a specially crafted request. The combination of network attack vector, low attack complexity, and no privileges or user interaction means a single crafted HTTP request to an exposed plug-in-fronted endpoint is sufficient to attempt code execution in the web tier — a direct pathway toward back-end WebSphere systems, internal network pivoting, and data on the application server.

CVE-2026-8620 (CVSS 3.1 7.5, vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N) is classified CWE-444, Inconsistent Interpretation of HTTP Requests (HTTP Request/Response Smuggling), in the same plug-in. A discrepancy in how the plug-in parses request framing (for example, ambiguous or conflicting Content-Length and Transfer-Encoding handling) versus the front-end web server or the back-end WAS allows an attacker to desynchronize the request stream, smuggle a second request past front-end inspection, poison shared connections, and reach paths or controls that perimeter defenses (WAFs, access rules) believe are protected. The Scope:Changed metric reflects that the impact crosses the trust boundary between the front-end and back-end tiers.

Analyst assessment: the two flaws reside in the same request-processing component and are plausibly chainable — request smuggling (CVE-2026-8620) to bypass perimeter inspection or reach a restricted code path, combined with the code-injection primitive (CVE-2026-8633) to achieve execution. IBM's bulletin documents the two as distinct issues remediated together and does not assert an exploit chain; the chaining here is Threadlinqs analyst hypothesis based on component co-location and the typical smuggling-to-RCE pattern, not vendor-confirmed.

As of this analysis (1 June 2026) there is no public proof-of-concept exploit, no reported in-the-wild exploitation, and neither CVE appears in the CISA Known Exploited Vulnerabilities catalog. IBM published the bulletin and an interim fix (APAR PH71342) concurrently with disclosure; permanent Fix Packs (9.0.5.28+ for the 9.0 stream, 8.5.5.30+ for the 8.5 stream) are slated for upcoming release cycles. No indicators of compromise (C2 infrastructure, malware hashes, attacker domains) have been published by any source; this record therefore documents analyst-derived behavioral and host hunting indicators rather than fabricated network artifacts.

## MITRE ATT&CK

- T1595 Active Scanning
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1505 Server Software Component
- T1211 Exploitation for Stealth
- T1552 Unsecured Credentials
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1210 Exploitation of Remote Services
- T1071 Application Layer Protocol

## Sources

- [NVD - CVE-2026-8633 Detail](https://nvd.nist.gov/vuln/detail/CVE-2026-8633)
- [NVD - CVE-2026-8620 Detail](https://nvd.nist.gov/vuln/detail/CVE-2026-8620)
- [IBM Security Bulletin: WebSphere Application Server and Liberty affected by multiple vulnerabilities when using Web Server Plug-ins (CVE-2026-8633, CVE-2026-8620)](https://www.ibm.com/support/pages/node/7274072)
- [IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request](https://cybersecuritynews.com/ibm-websphere-server-remote-code-execution/)
- [WebSphere Remote Code Execution Defended with New IBM Security Fixes](https://securityonline.info/websphere-remote-code-execution-patch/)
- [IBM WebSphere Application Server Remote Code Execution Vulnerability](https://www.hkcert.org/security-bulletin/ibm-websphere-application-server-remote-code-execution-vulnerability_20250627)
- [IBM Product Security Update Advisory - ASEC](https://asec.ahnlab.com/en/93899/)
- [A Vulnerability in IBM WebSphere Application Server Could Allow for Remote Code Execution - UCLA OCISO](https://ociso.ucla.edu/news/vulnerability-ibm-websphere-application-server-could-allow-remote-code-execution)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0650
