What is CVE-2026-15280?
A path-segment injection vulnerability exists in the collective routing mechanism of IBM WebSphere Application Server - Liberty ND Collective Controller, affecting versions 17.0.0.3 through 26.0.0.8. Immediate patching from IBM is required to mitigate potential exploitation.
Azərbaycanca: IBM WebSphere Application Server - Liberty ND Collective Controller-in kollektiv marşrutlaşdırma mexanizmində path-segment injection boşluğu aşkarlanıb. Bu zəiflik 17.0.0.3-dən 26.0.0.8-ə qədər versiyaları əhatə edir. Mümkün istismarın qarşısını almaq üçün dərhal rəsmi IBM yaması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: IBM
FAQ2
Which versions of IBM WebSphere Application Server - Liberty ND are affected by the CVE-2026-15280 path-segment injection vulnerability?
Versions 17.0.0.3 through 26.0.0.8 are affected by this vulnerability.
What action is required to mitigate potential exploitation of CVE-2026-15280?
Immediate patching from IBM is required to mitigate potential exploitation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.