Executive brief
IBM WebSphere Application Server Liberty, a platform for building and running cloud-native applications, is affected by a security flaw in its management component. An attacker could exploit this vulnerability to access sensitive files or directories on the server that should normally be restricted. This could lead to the exposure of confidential configuration data or internal system information.
Technical details
IBM WebSphere Application Server Liberty (versions 17.0.0.3 through 26.0.0.8) is vulnerable to path-segment injection (CWE-22) within the collective routing mechanism of the Collective Controller. The flaw exists when the 'collectiveController-1.0' feature is enabled. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the routing mechanism, potentially allowing them to bypass directory restrictions and read sensitive files. The vulnerability is addressed by applying the interim fix for APAR DT496531 or upgrading to Liberty Fix Pack 26.0.0.9 or later.
Affected products
- IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.8
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
- 2026-07-28: patched: Interim fix DT496531 released; Fix Pack 26.0.0.9 targeted for 3Q2026