SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14980

HIGH · CVSS 8.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 are vulnerable to cross-site request forgery (CSRF), which could enable attackers to execute Server-Side Request Forgery (SSRF) attacks with elevated privileges if the collectiveController-1.0 feature is active. Organizations using these affected versions should prioritize patching to mitigate the risk of unauthorized access and potential data exposure. This vulnerability poses a significant threat to any entity relying on these specific versions of the application server.

CVE
CVE-2026-14980
Severity
HIGH
CVSS
8.3
EPSS
0.24%

Original NVD Description

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.

Related CVEs

Other vulnerabilities affecting the same vendor(s)