IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
IBM WebSphere Application Server
Exploit
CVE-2026-8644
NVD
Refer to CVE-2026-8644 NVD advisory