CVE-2026-14529: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
Other sources
IBM WebSphere Application Server traditional and IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.0.0.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.5.5.31 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch DT495928 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH72053
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14529?
CVE-2026-14529 has a critical severity rating of 9.4.
How do I fix CVE-2026-14529?
To mitigate CVE-2026-14529, disable the SIP container feature if it is not required for your application.
What applications are affected by CVE-2026-14529?
CVE-2026-14529 affects IBM WebSphere Application Server versions 9.0 and 8.5, as well as IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8.
What type of vulnerability is CVE-2026-14529?
CVE-2026-14529 is a server-side request forgery (SSRF) vulnerability.
Is CVE-2026-14529 remotely exploitable?
Yes, CVE-2026-14529 can be exploited remotely due to its access vector.