Server-Side Request Forgery Vulnerability in IBM WebSphere Application Server
CVE-2026-14529

9.4CRITICAL

What is CVE-2026-14529?

IBM WebSphere Application Server versions 8.5 and 9.0, along with Liberty versions from 17.0.0.3 to 26.0.0.8, are exposed to a server-side request forgery (SSRF) vulnerability when the SIP container feature is enabled. This security flaw may allow attackers to send unauthorized requests from the server to internal resources, potentially leading to sensitive data exposure or other security risks.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

WebSphere Application Server - Liberty 17.0.0.3 <= 26.0.0.8

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.