What is CVE-2026-14980?
CVE-2026-14980 is a cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server - Liberty when the collectiveController-1.0 feature is enabled. This could allow an attacker to execute SSRF attacks with elevated privileges, affecting versions 17.0.0.3 through 26.0.0.8. Organizations should apply the security patches provided by IBM to mitigate this risk.
Azərbaycanca: CVE-2026-14980, IBM WebSphere Application Server - Liberty-nin collectiveController-1.0 funksiyası aktiv olduqda yaranan cross-site request forgery (CSRF) zəifliyidir. Bu, təcavüzkara yüksək imtiyazlarla SSRF hücumları həyata keçirməyə imkan verə bilər. Təsirlənmiş versiyaları (17.0.0.3 - 26.0.0.8) işlədən təşkilatlar IBM-in təqdim etdiyi təhlükəsizlik yamalarını tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-352; shared vendor: IBM
FAQ2
Which software is affected by CVE-2026-14980?
CVE-2026-14980 affects IBM WebSphere Application Server - Liberty.
Which versions need to be updated to mitigate CVE-2026-14980?
Versions 17.0.0.3 through 26.0.0.8 are affected, so IBM's security patches must be applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.