Server-Side Request Forgery Vulnerability in IBM WebSphere Application Server
CVE-2026-14529
9.4CRITICAL
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 29 July 2026
What is CVE-2026-14529?
IBM WebSphere Application Server versions 8.5 and 9.0, along with Liberty versions from 17.0.0.3 to 26.0.0.8, are exposed to a server-side request forgery (SSRF) vulnerability when the SIP container feature is enabled. This security flaw may allow attackers to send unauthorized requests from the server to internal resources, potentially leading to sensitive data exposure or other security risks.
Affected Version(s)
WebSphere Application Server 9.0
WebSphere Application Server 8.5
WebSphere Application Server - Liberty 17.0.0.3 <= 26.0.0.8