CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-14529

Critical · CVSS 9.4
CVSS
9.4
nvd
EPSS
0.33%
26th pct
KEV
No
Class
other
CWE-306

Description

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

References

Status: profiled · ingested 2026-08-04T18:00:54.000Z