Executive brief
IBM WebSphere Application Server Liberty is an application platform that enterprises use to host and run business-critical Java applications. When Liberty's collective features (collectiveController or collectiveMember) are enabled, an authenticated attacker with low privileges can escalate their access to gain high-level permissions, potentially leading to unauthorized control over the application server and its hosted applications.
Technical details
This is an improper authorization vulnerability (CWE-285) affecting the collective controller and member features in Liberty. An authenticated attacker (PR:L) can exploit this over the network (AV:N) without additional user interaction (UI:N) to escalate privileges and gain high-impact access to confidentiality and integrity of the system. The vulnerability requires the collectiveController-1.0 or collectiveMember-1.0 feature to be explicitly enabled. IBM recommends upgrading to Liberty Fix Pack 26.0.0.9 or later (targeted availability Q3 2026), or applying the interim fix for APAR DT497580.
Affected products
- IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8
Timeline
- 2026-08-12: disclosed