CVE-2026-15280: IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.
Other sources
IBM WebSphere Application Server - Liberty ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch DT496531
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15280?
The severity of CVE-2026-15280 is rated high, with a CVSS score of 7.5.
What type of vulnerability is CVE-2026-15280?
CVE-2026-15280 is a remote code execution and path-segment injection vulnerability.
Which versions of IBM WebSphere Application Server Liberty are affected by CVE-2026-15280?
IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 ND Collective Controller are affected by CVE-2026-15280.
How can I mitigate CVE-2026-15280?
Mitigation for CVE-2026-15280 involves updating IBM WebSphere Application Server - Liberty to an unaffected version.
What impact does CVE-2026-15280 have on systems?
CVE-2026-15280 can potentially allow an attacker to execute arbitrary code on the affected systems.