Junglewise Threat Intelligence

CVE-2026-14446: IBM WebSphere Application Server privilege escalation in administrative console

CVE-2026-14446 · Severity: critical · CVSS 9.8 · Published 2026-07-28

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server, a platform used to host and run enterprise Java applications, contains a critical security flaw in its administrative console. This vulnerability allows an unauthorized person to bypass security controls and gain administrative privileges over the server. If exploited, an attacker could take full control of the application environment, potentially leading to the theft of sensitive data, service outages, or unauthorized modification of business applications.

Technical details

IBM WebSphere Application Server is vulnerable to a privilege escalation flaw (CWE-306) within its administrative console. The root cause is a failure to require authentication for critical functions, allowing a remote, unauthenticated attacker to bypass access controls. By sending a specially crafted request over the network, an attacker can gain administrative rights, leading to a complete compromise of confidentiality, integrity, and availability. IBM has released interim fixes for APAR DT496500 and recommends upgrading to fix packs 9.0.5.29 or 8.5.5.31.

Affected products

  • IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.30

Timeline

  • 2026-07-28: disclosed: Initial publication of the security bulletin by IBM.
  • 2026-07-28: patched: Interim fixes released for affected versions.

References

Related threats