CVE-2026-11546: IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
Other sources
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71841
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11546?
The severity of CVE-2026-11546 is critical with a CVSS score of 9.8.
How do I fix CVE-2026-11546?
To fix CVE-2026-11546, disable the adminCenter-1.0 feature if it is not needed and ensure you are using an updated version of IBM WebSphere Application Server Liberty.
What systems are affected by CVE-2026-11546?
CVE-2026-11546 affects IBM WebSphere Application Server Liberty versions from 17.0.0.3 to 26.0.0.7.
What type of vulnerability is CVE-2026-11546?
CVE-2026-11546 is a server-side request forgery (SSRF) vulnerability.
What are the potential impacts of CVE-2026-11546?
If exploited, CVE-2026-11546 may allow an attacker to perform unauthorized actions on behalf of the vulnerable server.