
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11714 is a Server-Side Request Forgery (SSRF) vulnerability in IBM WebSphere Application Server - Liberty affecting versions 17.0.0.3 through 26.0.0.7 when the apiDiscovery-1.0 feature is enabled. The vulnerability was published on June 30, 2026, and a patch is available as of version 26.0.0.8. It carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, while IBM's own advisory scores it at 8.5 (High) using a scoped vector (GitHub Advisory, IBM Advisory).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where the web server receives a crafted URL or request and retrieves its contents without sufficiently validating the destination. The attack vector is network-based and requires low privileges (authenticated user), with no user interaction needed. The flaw is specifically triggered when the apiDiscovery-1.0 feature is enabled in the Liberty server configuration, allowing an attacker to craft requests that cause the server to make unintended HTTP requests to internal or external systems (GitHub Advisory, IBM Advisory).
Successful exploitation allows an authenticated attacker to leverage the WebSphere Liberty server as a proxy to reach internal systems and services that would otherwise be inaccessible, effectively bypassing network segmentation and access controls. The primary impact is high confidentiality loss — sensitive data from internal services (e.g., metadata endpoints, internal APIs, or cloud instance metadata) can be exfiltrated. Integrity impact is assessed as low (limited data modification possible), and availability is not directly affected according to IBM's scoring (GitHub Advisory, IBM Advisory).
apiDiscovery-1.0 feature is enabled (e.g., by probing known API discovery endpoints such as /ibm/api/explorer).http://169.254.169.254/latest/meta-data/ for cloud metadata, or internal service endpoints).169.254.169.254), or unusual external hosts./ibm/api/explorer or related apiDiscovery-1.0 endpoints with unusual or encoded URL parameters; server-initiated requests to internal services appearing in network flow logs.apiDiscovery-1.0 feature in server.xml on externally accessible Liberty instances running versions 17.0.0.3 through 26.0.0.7.IBM has released a fix in WebSphere Application Server Liberty version 26.0.0.8; organizations should upgrade immediately (IBM Advisory). As an interim workaround, disable the apiDiscovery-1.0 feature in server.xml if it is not required for operations. Additionally, implement network segmentation to restrict outbound connections from the Liberty server to only necessary internal services, and monitor/restrict outbound HTTP traffic from the application server process.
Tenable has published a Nessus detection plugin (ID 324008) for this vulnerability, enabling automated scanning of affected Liberty instances (Tenable Plugin). No significant public researcher commentary or social media discussion has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."