
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14915 is a privilege escalation vulnerability in IBM WebSphere Application Server (WAS) Liberty that allows a privileged user to gain additional unauthorized access to the application server. It affects IBM WAS Liberty versions 17.0.0.3 through 26.0.0.3, as well as downstream IBM products including SPSS Collaboration and Deployment Services and IBM CICS TX Advanced. The vulnerability was published on March 25, 2026, and is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). It carries a CVSS v3.1 base score of 7.2 (High) per NVD (IBM Support, Red Hat CVE).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), indicating that the vulnerability involves improper access controls that expose sensitive data or capabilities to actors who should not have access. The attack vector is network-based, requires no user interaction, and has low attack complexity, but does require high privileges — meaning an already-privileged user can exploit the flaw to escalate their access further within the Liberty application server. The specific mechanism by which privilege escalation occurs has not been publicly detailed in available technical write-ups, and no public proof-of-concept exploit code has been reported (IBM Support, Feedly).
Successful exploitation allows a privileged user to gain additional unauthorized access to the IBM WAS Liberty application server, with potential high impact on confidentiality, integrity, and availability of the affected system. This could result in exposure of sensitive application data, unauthorized modification of server configurations or data, and disruption of application services. The vulnerability also affects downstream IBM products (SPSS Collaboration and Deployment Services, IBM CICS TX Advanced), broadening the potential attack surface in enterprise environments (IBM Support, IBM CICS TX Advisory).
IBM has released a patch in WebSphere Application Server Liberty version 26.0.0.4, which resolves this vulnerability. Administrators should upgrade all affected Liberty instances from versions 17.0.0.3–26.0.0.3 to version 26.0.0.4 or later as the primary remediation. As interim measures, organizations should apply the principle of least privilege to limit privileged account access, audit and monitor privileged user activities, and review access controls on affected systems. Downstream products (SPSS Collaboration and Deployment Services, IBM CICS TX Advanced) also require separate patches per their respective IBM advisories (IBM Support, IBM SPSS Advisory, IBM CICS TX Advisory).
CSO Online reported that seven IBM WebSphere Liberty flaws, potentially including CVE-2025-14915, could be chained together to achieve full server takeover, highlighting the compounded risk of these vulnerabilities in enterprise deployments (CSO Online). The Open Liberty project published a blog post for the 26.0.0.4 release addressing the patched vulnerabilities (Open Liberty Blog). Tenable added Nessus detection plugins (IDs 303560 and 313185) for this CVE, enabling automated scanning of affected environments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."