PT-2026-65599 · Ibm · Ibm Websphere Application Server

CVE-2026-14512

·

Published

2026-07-28

·

Updated

2026-08-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server 9.0 IBM WebSphere Application Server 8.5 traditional
Description Pre-authentication unsafe deserialization allows a remote attacker to bypass authentication or execute arbitrary code. Unsafe deserialization occurs when untrusted data is used to abuse the logic of an application to execute malicious code or bypass security controls.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14512

Affected Products

Ibm Websphere Application Server