What is CVE-2026-14976?
This critical vulnerability allows Remote Code Execution on IBM WebSphere Application Server (Liberty) when the collectiveController-1.0 feature is enabled. Versions 17.0.0.3 through 26.0.0.8 are affected; it is strongly recommended to immediately apply the vendor-supplied security patch or disable the vulnerable feature.
Azərbaycanca: Bu kritik zəiflik, IBM WebSphere Application Server (Liberty) məhsulunda collectiveController-1.0 funksiyası aktiv olduqda uzaqdan kod icrasına (Remote Code Execution) imkan verir. 17.0.0.3 ilə 26.0.0.8 arası versiyalar təsirlənir; dərhal istehsalçı tərəfindən təqdim olunan təhlükəsizlik yamasının tətbiqi və ya funksiyanın deaktiv edilməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: IBM
FAQ2
Under what condition is the Remote Code Execution (RCE) risk for CVE-2026-14976 activated?
This critical vulnerability can only be exploited when the collectiveController-1.0 feature is enabled on the IBM WebSphere Application Server (Liberty) environment.
Which versions are affected by CVE-2026-14976 and what is the primary recommendation?
Versions 17.0.0.3 through 26.0.0.8 are affected. It is recommended to immediately apply the vendor-supplied security patch or disable the collectiveController-1.0 feature.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.