IBM WebSphere Application Server Administrative Console Broken Access Control (CVE-2026-14446)
criticalOtherIBM WebSphere Application Server versions 9.0 and 8.5 contain a critical broken access control vulnerability in the administrative console that allows privilege escalation. Exploitation could grant an attacker administrative control over the application server, enabling full compromise of hosted applications and backend services. Given the CVSS score of 9.8, this vulnerability is likely remotely exploitable with low complexity and no required privileges.
Updated Jul 29, 2026 · CVSS 9.8