Skip to content
TrustList
News

IBM lists five WebSphere Liberty flaws fixed in 26.0.0.10

Editorial

By TrustList Editorial

The medium-severity bulletin covers every Liberty release from 17.0.0.3 to 26.0.0.9, offers no workaround, and gives October as the expected fix pack date.

About IBM lists five WebSphere Liberty flaws fixed in 26.0.0.10

IBM lists five WebSphere Liberty flaws fixed in 26.0.0.10

6 October 2026: IBM has published a security bulletin for WebSphere Application Server Liberty covering five vulnerabilities, all scored medium. They affect every Liberty release from 17.0.0.3 through 26.0.0.9, and the fix is Liberty fix pack 26.0.0.10 or later. IBM identifies no workaround. It gives the fix pack's availability as projected for October 2026, so teams running Liberty may have to wait for the download before they can act.

Not yet independently verified. IBM gives the date of Liberty fix pack 26.0.0.10 as projected for October 2026, so it may not yet be downloadable. No exploitation is reported in the bulletin. We will update this when it can be confirmed, and remove this note.

The five CVEs

IBM's bulletin lists these scores and descriptions:

  • CVE-2026-14909, CVSS 6.5: information disclosure in the restConnector-2.0 feature, where an authenticated attacker could reach sensitive data.
  • CVE-2026-77816, CVSS 6.5: improper certificate validation in the administrative client, which exposes it to a man-in-the-middle attack.
  • CVE-2026-11713, CVSS 5.4: incorrect authorization that allows privilege escalation when restConnector-2.0 is enabled.
  • CVE-2026-79715, CVSS 5.5: path traversal that lets a local attacker write files outside the intended directories.
  • CVE-2026-14532, CVSS 4.3: an integer overflow that lets an attacker with the Reader role obtain version information and cause an uncaught exception.

Where the exposure sits

Two of the five depend on the restConnector-2.0 feature. Teams can check their server configuration for that feature to see whether the information disclosure and privilege escalation paths apply to them. The certificate validation flaw concerns the administrative client, so it matters most where administrators connect across networks they do not fully control. The path traversal needs local access.

Hong Kong's CERT issued its own summary on 8 October and also rates the group medium risk, pointing readers to IBM's page for the fix.

The wait for the fix pack

Because the bulletin offers no workaround, the interim options are limits on who holds the Reader role and who can reach the REST connector. IBM has not said, in the bulletin we read, whether any of the five has been used against a live system.

Company profile on TrustList: IBM

Related on TrustList:

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy