IBM WSA Liberty 17-26 CSRF SSRF via collectiveController
CVE-2026-14980 Published on July 30, 2026

IBM WebSphere Application Server Liberty is affected by a cross-site request forgery
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-14980 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and a small impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
LOW

Weakness Type

Improper Privilege Management

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2026-14980

Want to know whenever a new CVE is published for IBM Websphere Application Server Liberty? stack.watch will email you.

 

Affected Versions

IBM WebSphere Application Server - Liberty: