VYPR
High severity7.3NVD Advisory· Published May 26, 2026· Updated May 26, 2026

CVE-2026-8835

CVE-2026-8835

Description

IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM HTTP Server 8.5 and 9.0 contain an invalid pointer dereference vulnerability that allows a privileged authenticated user to expose sensitive information or cause a denial of service.

Vulnerability

IBM HTTP Server versions 8.5 and 9.0 are vulnerable to an invalid pointer dereference (CWE-822). This occurs when a privileged user authenticated to the Administration Server interacts with the server. The vulnerability is present in the Administration Server component. [1]

Exploitation

To exploit this vulnerability, an attacker must be a privileged user with authentication to the Administration Server. The attack vector is adjacent network (AV:A), requiring low complexity and no user interaction. The attacker can send crafted requests to trigger the invalid pointer dereference. [1]

Impact

Successful exploitation can lead to exposure of sensitive information (confidentiality impact: high) and denial of service (availability impact: high). There is no integrity impact. The attack achieves high confidentiality and availability compromise without requiring elevated privileges beyond the initial authentication. [1]

Mitigation

IBM has released security updates for IBM HTTP Server. Customers are advised to apply the fixes as specified in the security bulletin [1]. As a workaround, restrict access to the Administration Server to trusted users.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.