Junglewise Threat Intelligence

CVE-2026-14976: IBM WebSphere Application Server Liberty RCE in collectiveController

CVE-2026-14976 · Severity: high · CVSS 7.1 · Published 2026-07-28

Technologies: IBM WebSphere Application Server Liberty. Vendors: IBM.

Executive brief

IBM WebSphere Application Server Liberty, a popular platform for building and running cloud-native applications, is vulnerable to a security flaw when the 'collectiveController-1.0' feature is enabled. This vulnerability could allow an attacker to execute unauthorized commands on the server, potentially leading to a full system takeover or data theft. Organizations using this specific management feature should apply the available security updates immediately to protect their operations.

Technical details

IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 are vulnerable to Remote Code Execution (RCE) due to missing authentication for a critical function (CWE-306) within the collectiveController-1.0 feature. The vulnerability requires the attacker to be on an adjacent network and involves high complexity, including a requirement for user interaction. If successfully exploited, an attacker can execute arbitrary code on the host system. IBM has released interim fix DT496531 and recommends upgrading to Liberty Fix Pack 26.0.0.9 or later to remediate the issue.

Affected products

  • IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.8

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory
  • 2026-07-28: patched: Interim fix DT496531 released; Fix Pack 26.0.0.9 targeted for 3Q2026

References

Related threats