IBM lists five WebSphere Liberty flaws fixed in 26.0.0.10
EditorialBy TrustList Editorial
The medium-severity bulletin covers every Liberty release from 17.0.0.3 to 26.0.0.9, offers no workaround, and gives October as the expected fix pack date.
- Cybersecurity
- Vulnerability Management
- Java EE
- Java
About IBM lists five WebSphere Liberty flaws fixed in 26.0.0.10
IBM lists five WebSphere Liberty flaws fixed in 26.0.0.10
6 October 2026: IBM has published a security bulletin for WebSphere Application Server Liberty covering five vulnerabilities, all scored medium. They affect every Liberty release from 17.0.0.3 through 26.0.0.9, and the fix is Liberty fix pack 26.0.0.10 or later. IBM identifies no workaround. It gives the fix pack's availability as projected for October 2026, so teams running Liberty may have to wait for the download before they can act.
Not yet independently verified. IBM gives the date of Liberty fix pack 26.0.0.10 as projected for October 2026, so it may not yet be downloadable. No exploitation is reported in the bulletin. We will update this when it can be confirmed, and remove this note.
The five CVEs
IBM's bulletin lists these scores and descriptions:
- CVE-2026-14909, CVSS 6.5: information disclosure in the restConnector-2.0 feature, where an authenticated attacker could reach sensitive data.
- CVE-2026-77816, CVSS 6.5: improper certificate validation in the administrative client, which exposes it to a man-in-the-middle attack.
- CVE-2026-11713, CVSS 5.4: incorrect authorization that allows privilege escalation when restConnector-2.0 is enabled.
- CVE-2026-79715, CVSS 5.5: path traversal that lets a local attacker write files outside the intended directories.
- CVE-2026-14532, CVSS 4.3: an integer overflow that lets an attacker with the Reader role obtain version information and cause an uncaught exception.
Where the exposure sits
Two of the five depend on the restConnector-2.0 feature. Teams can check their server configuration for that feature to see whether the information disclosure and privilege escalation paths apply to them. The certificate validation flaw concerns the administrative client, so it matters most where administrators connect across networks they do not fully control. The path traversal needs local access.
Hong Kong's CERT issued its own summary on 8 October and also rates the group medium risk, pointing readers to IBM's page for the fix.
The wait for the fix pack
Because the bulletin offers no workaround, the interim options are limits on who holds the Reader role and who can reach the REST connector. IBM has not said, in the bulletin we read, whether any of the five has been used against a live system.
Company profile on TrustList: IBM
Related on TrustList:
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- Java EE
- Java
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.