Remote Code Execution Vulnerability in IBM WebSphere Application Server - Liberty
CVE-2026-14976

7.1HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
28 July 2026

What is CVE-2026-14976?

IBM WebSphere Application Server - Liberty, versions 17.0.0.3 through 26.0.0.8, is vulnerable to a remote code execution issue when the collectiveController-1.0 feature is enabled. This vulnerability may allow attackers to execute arbitrary code on the server, posing significant security risks. Proper security measures and timely updates are critical for mitigating the impact of this vulnerability.

Affected Version(s)

WebSphere Application Server - Liberty 17.0.0.3 <= 26.0.0.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.