IBM WebSphere Liberty RCE via collectiveCtrl-1.0 (v17.0.0.3-26.0.0.8)
CVE-2026-14976 Published on July 28, 2026

IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2026-14976

Want to know whenever a new CVE is published for IBM Websphere Application Server Liberty? stack.watch will email you.

 

Affected Versions

IBM WebSphere Application Server - Liberty: