Cross-Site Request Forgery in IBM WebSphere Application Server - Liberty
CVE-2026-14980
8.3HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 30 July 2026
What is CVE-2026-14980?
IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 are susceptible to a cross-site request forgery attack. When the collectiveController-1.0 feature is enabled, this vulnerability can be exploited to carry out Server-Side Request Forgery (SSRF) attacks, potentially allowing attackers to access and manipulate sensitive backend servers and data.
Affected Version(s)
WebSphere Application Server - Liberty 17.0.0.3 <= 26.0.0.8