
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-10571 is a denial-of-service vulnerability in IBM WebSphere Application Server - Liberty caused by insecure deserialization in the restConnector-2.0 feature. It affects versions 17.0.0.3 through 26.0.0.8 (fixed in 26.0.0.9). A low-privileged administrative user with network access can exploit this flaw to consume system resources and render the server unavailable. It carries a CVSS v3.1 base score of 5.3 (Medium) per NVD, and 5.7 (Medium) per ENISA (IBM Advisory, ENISA EUVD).
The root cause is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). When the restConnector-2.0 feature is enabled, the application server deserializes untrusted data supplied by an authenticated low-privileged administrative user, allowing the attacker to trigger excessive resource consumption. Exploitation requires network access and low-level administrative privileges, and is rated as high attack complexity, meaning it is not trivially automated (IBM Advisory, Tenable Plugin).
Successful exploitation results in a denial-of-service condition, exhausting system resources on the affected WebSphere Liberty instance and causing it to become unavailable to legitimate users. There is no confidentiality or integrity impact — the vulnerability is limited to availability. The scope is unchanged, meaning the impact is confined to the vulnerable component itself (IBM Advisory, ENISA EUVD).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The NVD SSVC assessment confirms exploitation is "none" and the attack is not automatable due to the high attack complexity and required authentication. The EPSS score is approximately 0.56%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (IBM Advisory, Tenable Plugin).
IBM has released a fix in WebSphere Application Server - Liberty version 26.0.0.9; upgrading to this version or later is the recommended remediation (IBM Advisory). If immediate patching is not feasible, the following interim mitigations should be applied:
restConnector-2.0 feature from the Liberty server configuration if it is not required.restConnector-2.0 endpoint to trusted administrative users and networks only.The vulnerability was covered by IT Jungle in the context of a broader IBM i PTF security patch roundup published on August 17, 2026, noting a large volume of security vulnerability patches released that week (IT Jungle). Tenable added a Nessus detection plugin (ID 335000) shortly after disclosure, and the vulnerability was indexed by AUSCERT, ENISA EUVD, and VulDB. No notable independent researcher commentary or significant social media discussion has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."