Cross-Site Request Forgery in IBM WebSphere Application Server - Liberty
CVE-2026-2482

3.1LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
29 July 2026

What is CVE-2026-2482?

IBM WebSphere Application Server - Liberty contains a cross-site request forgery vulnerability that could permit an attacker to initiate malicious actions through a web application. An attacker can exploit this flaw when a user is tricked into performing unintended operations, leading to unauthorized changes or access to sensitive information. Organizations using affected versions should apply security patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

WebSphere Application Server - Liberty 17.0.0.3 <= 26.0.0.8

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.