CVE-2026-14446: IBM WebSphere Application Server is affected by a privilege escalation
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
Other sources
IBM WebSphere Application Server is vulnerable to broken access control/privilege escalation in the administrative console.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.31Patch DT496500 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29Patch DT496500 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Patch DT496500
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14446?
The severity of CVE-2026-14446 is rated as critical with a CVSS score of 9.8.
What does CVE-2026-14446 affect?
CVE-2026-14446 affects IBM WebSphere Application Server versions 9.0 and 8.5.
What type of vulnerability is CVE-2026-14446?
CVE-2026-14446 is classified as a privilege escalation vulnerability due to broken access control.
How do I fix CVE-2026-14446?
To fix CVE-2026-14446, update your IBM WebSphere Application Server to the latest patched version provided by IBM.
What are the risks associated with CVE-2026-14446?
The risks associated with CVE-2026-14446 include unauthorized access to sensitive administrative functions, potentially compromising system integrity.