CVE-2025-14915
IBM WebSphere Application Server vulnerability analysis and mitigation

Overview

CVE-2025-14915 is a privilege escalation vulnerability in IBM WebSphere Application Server (WAS) Liberty that allows a privileged user to gain additional unauthorized access to the application server. It affects IBM WAS Liberty versions 17.0.0.3 through 26.0.0.3, as well as downstream IBM products including SPSS Collaboration and Deployment Services and IBM CICS TX Advanced. The vulnerability was published on March 25, 2026, and is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). It carries a CVSS v3.1 base score of 7.2 (High) per NVD (IBM Support, Red Hat CVE).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), indicating that the vulnerability involves improper access controls that expose sensitive data or capabilities to actors who should not have access. The attack vector is network-based, requires no user interaction, and has low attack complexity, but does require high privileges — meaning an already-privileged user can exploit the flaw to escalate their access further within the Liberty application server. The specific mechanism by which privilege escalation occurs has not been publicly detailed in available technical write-ups, and no public proof-of-concept exploit code has been reported (IBM Support, Feedly).

Impact

Successful exploitation allows a privileged user to gain additional unauthorized access to the IBM WAS Liberty application server, with potential high impact on confidentiality, integrity, and availability of the affected system. This could result in exposure of sensitive application data, unauthorized modification of server configurations or data, and disruption of application services. The vulnerability also affects downstream IBM products (SPSS Collaboration and Deployment Services, IBM CICS TX Advanced), broadening the potential attack surface in enterprise environments (IBM Support, IBM CICS TX Advisory).

Mitigation and workarounds

IBM has released a patch in WebSphere Application Server Liberty version 26.0.0.4, which resolves this vulnerability. Administrators should upgrade all affected Liberty instances from versions 17.0.0.3–26.0.0.3 to version 26.0.0.4 or later as the primary remediation. As interim measures, organizations should apply the principle of least privilege to limit privileged account access, audit and monitor privileged user activities, and review access controls on affected systems. Downstream products (SPSS Collaboration and Deployment Services, IBM CICS TX Advanced) also require separate patches per their respective IBM advisories (IBM Support, IBM SPSS Advisory, IBM CICS TX Advisory).

Community reactions

CSO Online reported that seven IBM WebSphere Liberty flaws, potentially including CVE-2025-14915, could be chained together to achieve full server takeover, highlighting the compounded risk of these vulnerabilities in enterprise deployments (CSO Online). The Open Liberty project published a blog post for the 26.0.0.4 release addressing the patched vulnerabilities (Open Liberty Blog). Tenable added Nessus detection plugins (IDs 303560 and 313185) for this CVE, enabling automated scanning of affected environments.

Additional resources


SourceThis report was generated using AI

Related IBM WebSphere Application Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-11541CRITICAL9.8
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026
CVE-2026-11714CRITICAL9.8
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026
CVE-2026-11712CRITICAL9.3
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026
CVE-2026-11806HIGH7.5
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026
CVE-2026-11594MEDIUM6.1
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management