CVE-2026-11714: IBM WebSphere Application Server Liberty is affected by an authorization bypass vulnerability
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
Other sources
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.8 - Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Patch PH71873
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11714?
CVE-2026-11714 has a high severity rating of 8.5.
What systems are vulnerable to CVE-2026-11714?
CVE-2026-11714 affects IBM WebSphere Application Server Liberty versions from 17.0.0.3 through 26.0.0.7.
What type of vulnerability is CVE-2026-11714?
CVE-2026-11714 is classified as a server-side request forgery (SSRF) vulnerability.
How can I mitigate CVE-2026-11714?
To mitigate CVE-2026-11714, disable the apiDiscovery-1.0 feature if it is not needed.
What impact can CVE-2026-11714 have on my system?
CVE-2026-11714 can lead to unauthorized access and manipulation of server requests.