CVE-2026-14980: IBM WebSphere Application Server Liberty is affected by a cross-site request forgery
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71678
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14980?
The severity of CVE-2026-14980 is rated high with a score of 8.8.
How do I fix CVE-2026-14980?
To fix CVE-2026-14980, upgrade IBM WebSphere Application Server Liberty to version 26.0.0.9 or later.
What type of vulnerability is CVE-2026-14980?
CVE-2026-14980 is a cross-site request forgery (CSRF) vulnerability.
Which versions of IBM WebSphere Application Server Liberty are affected by CVE-2026-14980?
IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 are affected by CVE-2026-14980.
What could an attacker potentially do with CVE-2026-14980?
An attacker could perform server-side request forgery (SSRF) attacks with elevated privileges if the collectiveController-1.0 feature is enabled.