Junglewise Threat Intelligence

CVE-2026-11806: IBM WebSphere Application Server Liberty arbitrary file read in restConnector-2.0

CVE-2026-11806 · Severity: high · CVSS 7.2 · Published 2026-06-30

Technologies: IBM WebSphere Application Server Liberty. Vendors: IBM.

Executive brief

IBM WebSphere Application Server Liberty, a platform for developing and running Java applications, is affected by a security flaw when the restConnector-2.0 feature is enabled. An attacker with high-level administrative privileges could exploit this to read sensitive files from the server's file system. This could lead to the exposure of configuration data, credentials, or other private information, potentially compromising the entire application environment.

Technical details

IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.6 are vulnerable to an arbitrary file read. The issue is associated with CWE-444 (Inconsistent Interpretation of HTTP Requests / HTTP Request Smuggling) within the restConnector-2.0 feature. An authenticated attacker with high privileges can exploit this vulnerability over the network to read arbitrary files on the host system. IBM has released interim fix PH71719 and recommends upgrading to Liberty Fix Pack 26.0.0.7 or later to remediate the issue.

Affected products

  • IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.6

Timeline

  • 2026-06-23: advisory: Initial publication by IBM
  • 2026-06-30: disclosed: NVD publication date

References

Related threats