{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/websphere-application-server---liberty-17.0.0.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-15280"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WebSphere Application Server - Liberty 17.0.0.3","WebSphere Application Server - Liberty 17.0.0.4","WebSphere Application Server - Liberty 17.0.0.5","WebSphere Application Server - Liberty 17.0.0.6","WebSphere Application Server - Liberty 17.0.0.7","WebSphere Application Server - Liberty 17.0.0.8","WebSphere Application Server - Liberty 18.0.0.1","WebSphere Application Server - Liberty 18.0.0.2","WebSphere Application Server - Liberty 18.0.0.3","WebSphere Application Server - Liberty 18.0.0.4","WebSphere Application Server - Liberty 19.0.0.1","WebSphere Application Server - Liberty 19.0.0.2","WebSphere Application Server - Liberty 19.0.0.3","WebSphere Application Server - Liberty 19.0.0.4","WebSphere Application Server - Liberty 20.0.0.1","WebSphere Application Server - Liberty 20.0.0.2","WebSphere Application Server - Liberty 20.0.0.3","WebSphere Application Server - Liberty 20.0.0.4","WebSphere Application Server - Liberty 21.0.0.1","WebSphere Application Server - Liberty 21.0.0.2","WebSphere Application Server - Liberty 21.0.0.3","WebSphere Application Server - Liberty 21.0.0.4","WebSphere Application Server - Liberty 22.0.0.1","WebSphere Application Server - Liberty 22.0.0.2","WebSphere Application Server - Liberty 22.0.0.3","WebSphere Application Server - Liberty 22.0.0.4","WebSphere Application Server - Liberty 23.0.0.1","WebSphere Application Server - Liberty 23.0.0.2","WebSphere Application Server - Liberty 23.0.0.3","WebSphere Application Server - Liberty 23.0.0.4","WebSphere Application Server - Liberty 24.0.0.1","WebSphere Application Server - Liberty 24.0.0.2","WebSphere Application Server - Liberty 24.0.0.3","WebSphere Application Server - Liberty 24.0.0.4","WebSphere Application Server - Liberty 25.0.0.1","WebSphere Application Server - Liberty 25.0.0.2","WebSphere Application Server - Liberty 25.0.0.3","WebSphere Application Server - Liberty 25.0.0.4","WebSphere Application Server - Liberty 26.0.0.1","WebSphere Application Server - Liberty 26.0.0.2","WebSphere Application Server - Liberty 26.0.0.3","WebSphere Application Server - Liberty 26.0.0.4","WebSphere Application Server - Liberty 26.0.0.5","WebSphere Application Server - Liberty 26.0.0.6","WebSphere Application Server - Liberty 26.0.0.7","WebSphere Application Server - Liberty 26.0.0.8"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-segment-injection","information-disclosure","websphere","ibm"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM has disclosed a path-segment injection vulnerability, identified as CVE-2026-15280, affecting its WebSphere Application Server - Liberty product. Specifically, versions 17.0.0.3 through 26.0.0.8 of the ND Collective Controller component are susceptible. This flaw resides within the collective routing mechanism, allowing an unauthenticated attacker to inject arbitrary path segments. This vulnerability is categorized as CWE-22, \u0026quot;Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'),\u0026quot; and carries a CVSS v3.1 Base Score of 7.5, indicating a high severity risk primarily due to its potential for high confidentiality impact. The vulnerability does not require authentication or user interaction for exploitation and can lead to unauthorized access to sensitive information on the affected server.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker sends a specially crafted HTTP request to a vulnerable IBM WebSphere Application Server - Liberty instance.\u003c/li\u003e\n\u003cli\u003eThe request is directed towards a component utilizing the collective routing mechanism of the server.\u003c/li\u003e\n\u003cli\u003eThe attacker embeds malicious path segments within the request, designed to bypass normal validation.\u003c/li\u003e\n\u003cli\u003eDue to the path-segment injection vulnerability (CVE-2026-15280), the collective routing mechanism fails to properly sanitize or validate these injected segments.\u003c/li\u003e\n\u003cli\u003eThis failure allows the attacker to manipulate the server's path resolution logic, enabling access to restricted directories or files.\u003c/li\u003e\n\u003cli\u003eThe server processes the request with the injected path, leading to unauthorized disclosure of sensitive information from the file system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-15280 can lead to significant information disclosure. Attackers capable of exploiting this path-segment injection vulnerability could gain unauthorized access to critical configuration files, user data, server logs, or other sensitive information stored on the affected IBM WebSphere Application Server - Liberty instances. While the vulnerability does not directly enable integrity modification or availability impact, the exposure of confidential data can have severe consequences, including intellectual property theft, privacy breaches, and further system compromise through credential harvesting or detailed reconnaissance. Organizations using affected versions are at risk of data exfiltration and compliance violations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-15280 immediately by upgrading IBM WebSphere Application Server - Liberty to a fixed version as specified in the IBM Corporation advisory at \u003ccode\u003ehttps://www.ibm.com/support/pages/node/7281633\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eReview network logs for unusual HTTP requests targeting the collective routing mechanism or containing atypical path segments, particularly those involving \u003ccode\u003eCWE-22\u003c/code\u003e characteristics.\u003c/li\u003e\n\u003cli\u003eImplement strong input validation and sanitization for all user-supplied data, especially in web application path parameters, to prevent future path-segment injection vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T21:29:03Z","date_published":"2026-07-28T21:29:03Z","id":"https://feed.craftedsignal.io/briefs/2026-07-ibm-websphere-path-injection/","summary":"A path-segment injection vulnerability (CVE-2026-15280) in the collective routing mechanism of IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 ND Collective Controller allows an unauthenticated attacker to inject arbitrary path segments, potentially leading to information disclosure.","title":"IBM WebSphere Application Server Liberty Path-Segment Injection Vulnerability (CVE-2026-15280)","url":"https://feed.craftedsignal.io/briefs/2026-07-ibm-websphere-path-injection/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7,"id":"CVE-2026-16184"},{"cvss":7.4,"id":"CVE-2026-14528"},{"cvss":9.8,"id":"CVE-2026-14446"},{"cvss":9.8,"id":"CVE-2026-14512"},{"cvss":7.5,"id":"CVE-2026-14981"},{"cvss":8.7,"id":"CVE-2026-15325"},{"cvss":8.7,"id":"CVE-2026-15064"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WebSphere Application Server 9.0","WebSphere Application Server 8.5","WebSphere Application Server - Liberty \u003e= 17.0.0.3 \u003c= 26.0.0.7","WebSphere Application Server - Liberty 17.0.0.3","WebSphere Application Server - Liberty 26.0.0.7","WebSphere Application Server (9.0)","WebSphere Application Server (8.5)","WebSphere Application Server - Liberty (\u003e= 17.0.0.3, \u003c= 26.0.0.7)","WebSphere Application Server - Liberty"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","authentication-bypass","websphere","broken-access-control","privilege-escalation","deserialization","RCE","server-side-request-forgery","cwe-502","http-smuggling","server-side","http-request-smuggling","web-vulnerability","cve"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM has identified a high-severity vulnerability, CVE-2026-16184, affecting its WebSphere Application Server versions 9.0 and 8.5. This flaw, categorized as a Missing Authorization (CWE-862), allows a remote, unauthenticated attacker to bypass the server's authentication mechanisms. By sending a specially crafted request, an attacker can gain unauthorized access to the application server. This vulnerability can lead to unauthorized information disclosure, data modification, or denial of service, depending on the accessed resources and the attacker's capabilities post-bypass. Organizations using affected WebSphere versions are advised to apply the necessary patches provided by IBM to mitigate the risk of exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eA remote, unauthenticated attacker identifies a public-facing IBM WebSphere Application Server instance running a vulnerable version (9.0 or 8.5).\u003c/li\u003e\n\u003cli\u003eThe attacker performs initial reconnaissance to understand the server's exposed endpoints and the expected authentication process.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a specific HTTP request designed to exploit the missing authorization vulnerability (CWE-862) within the WebSphere server's authentication logic.\u003c/li\u003e\n\u003cli\u003eThis crafted request is intentionally formed to bypass standard authentication checks, possibly by manipulating specific HTTP headers, cookies, URL parameters, or the request body content.\u003c/li\u003e\n\u003cli\u003eThe attacker sends this unauthenticated, crafted request to the vulnerable WebSphere Application Server.\u003c/li\u003e\n\u003cli\u003eThe server processes the request, and due to the underlying vulnerability, it fails to properly enforce authentication requirements, allowing the request to proceed as if authenticated.\u003c/li\u003e\n\u003cli\u003eConsequently, the attacker gains unauthorized access to resources, functionalities, or administrative interfaces within the application server without providing valid credentials.\u003c/li\u003e\n\u003cli\u003eWith unauthorized access, the attacker can potentially perform actions such as information disclosure, unauthorized data modification, or disrupt the availability of the server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-16184 could lead to a significant compromise of the affected IBM WebSphere Application Server instance. Attackers could gain unauthorized access to sensitive data, modify application configurations, or disrupt critical services, leading to a loss of confidentiality, integrity, and availability for applications hosted on the server. While specific victim counts or sectors are not detailed, any organization running unpatched versions of WebSphere Application Server 9.0 or 8.5, particularly those exposed to the internet, is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-16184 on all IBM WebSphere Application Server 9.0 and 8.5 instances immediately by applying the updates referenced in the IBM Corporation advisory \u003ccode\u003ehttps://www.ibm.com/support/pages/node/7281628\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eMonitor \u003ccode\u003ewebserver\u003c/code\u003e logs for suspicious unauthenticated requests, specifically looking for abnormal access patterns to sensitive endpoints.\u003c/li\u003e\n\u003cli\u003eImplement strong network segmentation and access controls to limit exposure of IBM WebSphere Application Server instances to untrusted networks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T21:30:35Z","date_published":"2026-07-28T20:21:12Z","id":"https://feed.craftedsignal.io/briefs/2026-07-ibm-websphere-auth-bypass/","summary":"A remote attacker can bypass authentication in IBM WebSphere Application Server versions 9.0 and 8.5 by sending a crafted unauthenticated request, potentially leading to unauthorized access and impact on confidentiality, integrity, and availability.","title":"IBM WebSphere Application Server Authentication Bypass Vulnerability (CVE-2026-16184)","url":"https://feed.craftedsignal.io/briefs/2026-07-ibm-websphere-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - WebSphere Application Server - Liberty 17.0.0.3","version":"https://jsonfeed.org/version/1.1"}