Impact
IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 are vulnerable to a privilege escalation when using Liberty collectives. The flaw allows an authenticated user who can access collective features to gain elevated privileges, potentially enabling unauthorized configuration changes or deployment of malicious components. This impacts confidentiality, integrity, and availability through improper access control (CWE-285).
Affected Systems
The affected product is IBM WebSphere Application Server Liberty. Clients running versions 17.0.0.3 up to 26.0.0.8 that have the collectiveController-1.0 or collectiveMember-1.0 features enabled are at risk. Identical impacts apply across all supported platforms for this Liberty line.
Risk and Exploitability
The CVSS score of 8.1 labels the vulnerability as high severity. No EPSS data is available and the issue is not listed in CISA KEV, indicating no confirmed exploitation yet. Nevertheless, attackers would need access to a Liberty environment with collective features enabled, which could be local or remote depending on the deployment. The recommended mitigation is to patch promptly, as exploitation risk remains significant in the absence of a fix.
OpenCVE Enrichment