CVE-2026-14512: IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
Other sources
IBM WebSphere Application Server traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 8.5.5.31Patch PH72166 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 9.0.5.29Patch PH72166
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14512?
The severity of CVE-2026-14512 is critical with a CVSS score of 9.8.
How do I fix CVE-2026-14512?
To fix CVE-2026-14512, upgrade to the patched version of IBM WebSphere Application Server as provided by IBM.
What types of attacks can CVE-2026-14512 enable?
CVE-2026-14512 can enable remote attackers to bypass authentication or execute arbitrary code.
Which versions of IBM WebSphere Application Server are affected by CVE-2026-14512?
IBM WebSphere Application Server 9.0 and 8.5 traditional are affected by CVE-2026-14512.
Is the exploitation of CVE-2026-14512 remotely accessible?
Yes, CVE-2026-14512 allows for remote exploitation due to its nature of pre-authentication unsafe deserialization.