{"id":"CVE-2026-11538","published":"2026-09-18T19:16:40.957","lastModified":"2026-09-24T15:58:10.653","description":"IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.","cvssScore":3.7,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-117"],"vendors":["ibm"],"products":["websphere application server"],"references":[{"url":"https://www.ibm.com/support/pages/node/7286610","tags":["Patch","Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":null}