IBM WebSphere Application Server Liberty is affected by a cross-site request forgery
CVE-2026-2482

3.1LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
29 July 2026

What is CVE-2026-2482?

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

Affected Version(s)

WebSphere Application Server - Liberty 17.0.0.3 <= 26.0.0.8

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.