Executive brief
IBM WebSphere Application Server Liberty, a platform for developing and running Java applications, is affected by a security flaw that could allow an attacker to trick a legitimate user into performing unintended actions. By convincing a user to visit a malicious link or website while they are logged into the application server, an attacker could execute unauthorized commands on the user's behalf. While the impact is limited, it could lead to unauthorized changes or actions within the application environment.
Technical details
IBM WebSphere Application Server Liberty (versions 17.0.0.3 through 26.0.0.8) contains a Cross-Site Request Forgery (CSRF) vulnerability (CWE-352). The flaw exists when the 'collectiveController-1.0' feature is enabled. An unauthenticated remote attacker can exploit this by tricking a victim into clicking a malicious link or visiting a specially crafted website, leading to the execution of unauthorized actions in the context of the victim's session. The attack requires user interaction and has a high attack complexity. IBM has released APAR PH71678 to address this issue, and the fix is included in Liberty Fix Pack 26.0.0.9.
Affected products
- IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.8
Timeline
- 2026-07-28: advisory: Initial publication by IBM
- 2026-07-29: disclosed: NVD publication date