What is CVE-2026-10571?
This vulnerability affects IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8. A low-privileged administrative user can exploit insecure deserialization to consume system resources and cause a Denial of Service when the restConnector-2.0 feature is enabled. System administrators should apply the necessary patches and review configurations regarding the restConnector-2.0 feature.
Azərbaycanca: Bu zəiflik IBM WebSphere Application Server Liberty-nin köhnə versiyalarında aşkarlanıb. Aşağı səlahiyyətli admin istifadəçi, restConnector-2.0 aktiv olduqda, etibarsız deserializasiya səbəbi ilə sistem resurslarını tükədərək xidmətə müdaxilə (Denial of Service) yarada bilər. Məsul sistem administratorları verilən versiyaları yeniləməli və restConnector-2.0 funksiyasını konfiqurasiya baxımından nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-502; shared vendor: IBM
FAQ2
Under what conditions can the CVE-2026-10571 vulnerability be exploited for a DoS attack?
The vulnerability can be exploited when the restConnector-2.0 feature is enabled and the attacker has access as a low-privileged administrative user. The attack leverages insecure deserialization.
What measures should be taken to protect against CVE-2026-10571?
System administrators should apply the necessary patches for IBM WebSphere Application Server Liberty and review configurations regarding the restConnector-2.0 feature.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.