VYPR
High severity7.7NVD Advisory· Published May 26, 2026· Updated May 26, 2026

CVE-2026-8856

CVE-2026-8856

Description

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM HTTP Server 8.5/9.0 denial of service via NULL pointer dereference in mod_ibm_upload when attacker has write config access.

Vulnerability

IBM HTTP Server versions 8.5 and 9.0 are vulnerable to denial of service via the optional module mod_ibm_upload. The bug is a NULL pointer dereference (CWE-476) reachable when an attacker has write access to parts of the server configuration. The affected module is not enabled by default, but can be activated in configurations where the attacker can modify server settings.

Exploitation

An attacker needs write access to the server configuration (e.g., via the Administration Server or file system). With that privilege, they can enable mod_ibm_upload and trigger the NULL pointer dereference by sending a crafted HTTP request. No authentication or network position beyond local or adjacent access is required; the attack is low complexity and requires no user interaction.

Impact

Successful exploitation causes a denial of service (availability loss, CVSS 7.5). No information disclosure or code execution occurs; the impact is limited to service disruption.

Mitigation

IBM has not disclosed a fix as of the publication date. Workarounds include disabling mod_ibm_upload if not needed, or restricting write access to server configuration to trusted administrators only. The vulnerability is not listed in KEV. Users should monitor IBM security bulletins for future patches.

References

[1] https://www.ibm.com/support/pages/node/7274065 — IBM HTTP Server multiple vulnerabilities bulletin.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.