CVE-2026-11806: IBM WebSphere Application Server Liberty is affected by a an arbitrary file read vulnerability
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
Other sources
IBM WebSphere Application Server Liberty is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.7Patch PH71719 - Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Patch PH71719
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11806?
CVE-2026-11806 has a high severity rating of 7.5.
How do I fix CVE-2026-11806?
To fix CVE-2026-11806, you should upgrade to IBM WebSphere Application Server Liberty version 26.0.0.7 or later.
What systems are affected by CVE-2026-11806?
CVE-2026-11806 affects IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.6 with the restConnector-2.0 feature enabled.
What is the nature of the vulnerability in CVE-2026-11806?
CVE-2026-11806 is an arbitrary file read vulnerability that could allow unauthorized access to files on the server.
What is the published date of CVE-2026-11806?
CVE-2026-11806 was published on June 23, 2026.