Junglewise Threat Intelligence

CVE-2026-14980: IBM WebSphere Application Server Liberty CSRF in collectiveController

CVE-2026-14980 · Severity: high · CVSS 8.3 · Published 2026-07-30

Executive brief

IBM WebSphere Application Server Liberty, a popular framework for building and deploying Java applications, is affected by a security flaw when the collective management feature is enabled. An attacker could trick a legitimate user into performing unintended actions that allow the attacker to make unauthorized requests to internal systems. This could lead to unauthorized access to sensitive data or internal services that are not normally exposed to the internet.

Technical details

IBM WebSphere Application Server Liberty is vulnerable to a Cross-Site Request Forgery (CSRF) attack specifically when the 'collectiveController-1.0' feature is enabled. The vulnerability stems from improper privilege management (CWE-269) during request handling. A remote attacker can exploit this by tricking an authenticated user into visiting a malicious website, which then triggers unauthorized requests. Successful exploitation allows the attacker to perform Server-Side Request Forgery (SSRF) attacks with elevated privileges. IBM has released interim fix PH71678 and recommends upgrading to Liberty Fix Pack 26.0.0.9 or later to remediate the issue.

Affected products

  • IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.8

Timeline

  • 2026-07-28: disclosed: Initial publication by IBM
  • 2026-07-30: advisory: NVD publication date

References

Related threats