CVE-2026-14446

Summary

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

Affected Software

VendorProductVersion RangeStatus
IBMWebSphere Application Server9.0affected
IBMWebSphere Application Server8.5affected

Weaknesses

  • CWE-306: CWE-306 Missing Authentication for Critical Function

References