Description
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Published: 2026-07-29
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a cross‑site request forgery that allows an attacker to craft a request that the victim’s browser will submit to the IBM WebSphere Application Server Liberty with the victim’s credentials, potentially leading to unauthorized manipulation of application data or configuration. This weakness is classified as CWE‑352 and would let an attacker perform any action that the victim’s account is permitted to execute, risking confidentiality, integrity, or availability of the affected resources.

Affected Systems

IBM WebSphere Application Server Liberty versions from 17.0.0.3 through 26.0.0.8 are affected when the collectiveController‑1.0 feature is enabled. The remediation is an interim fix for the affected products or a newer Liberty Fix Pack (26.0.0.9 or later). The vendor recommends first upgrading to the minimal required fix pack level before applying the interim fix PH71678, or you can simply deploy a later fix pack that contains the fix.

Risk and Exploitability

The CVSS base score is 3.1, indicating relatively low severity, and the EPSS score is less than 1 %, implying a very low probability of exploitation; this vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a web‑based forgery, requiring an authenticated user to visit a malicious site that sends a forged request to the vulnerable server. While the risk is modest, the potential for unauthorized activity warrants timely patching.

Generated by OpenCVE AI on August 3, 2026 at 13:04 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH71678. To determine if a feature is enabled for IBM WebSphere Application Server Liberty, refer to How to determine if Liberty is using a specific feature https://www.ibm.com/support/pages/node/6553910 .  For IBM WebSphere Application Server Liberty 17.0.0.3 - 26.0.0.8 using the collectiveController-1.0 feature(s):  · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH71678  https://www.ibm.com/support/pages/node/7281098 --OR-- · Apply Liberty Fix Pack 26.0.0.9 or later (targeted availability 3Q2026).  Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Verify whether the collectiveController-1.0 feature is enabled on your Liberty installations.
  • Upgrade to the minimal required fix pack level and apply the interim fix PH71678 (available from IBM support).
  • Alternatively, install Liberty Fix Pack 26.0.0.9 or later, which contains the fix.

Generated by OpenCVE AI on August 3, 2026 at 13:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm
Ibm websphere Application Server Liberty
Vendors & Products Ibm
Ibm websphere Application Server Liberty

Wed, 29 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Title IBM WebSphere Application Server Liberty is affected by a cross-site request forgery
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Ibm Websphere Application Server Websphere Application Server Liberty
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T15:19:30.028Z

Reserved: 2026-02-13T18:39:00.390Z

Link: CVE-2026-2482

cve-icon Vulnrichment

Updated: 2026-07-30T13:55:29.396Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T19:16:45.597

Modified: 2026-08-04T14:10:12.610

Link: CVE-2026-2482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:15:05Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)