
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1561 is a Server-Side Request Forgery (SSRF) vulnerability in IBM WebSphere Application Server Liberty that allows low-privileged remote attackers to send unauthorized requests from the affected system. It affects IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.3, as well as downstream IBM products including SPSS Collaboration and Deployment Services, IBM CICS TX Advanced, and IBM License Metric Tool v9. The vulnerability was published on March 25, 2026, with a patch released in version 26.0.0.4. It carries a CVSS v3.1 base score of 5.4 (Medium) (IBM Advisory, Red Hat CVE).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where the application fails to adequately validate or restrict URLs supplied by a low-privileged authenticated user before making server-side HTTP requests. An attacker with low-level network access and authenticated credentials can craft requests that cause the WebSphere Liberty server to issue outbound HTTP requests to arbitrary internal or external destinations. This can be leveraged for internal network enumeration or as a stepping stone to attack internal services that trust traffic originating from the WebSphere server. No specific vulnerable endpoint or technical write-up has been publicly disclosed beyond the vendor advisory (IBM Advisory, Red Hat CVE).
Successful exploitation results in low-level confidentiality and integrity impacts, with no direct availability impact. A remote attacker with low privileges can use the SSRF to enumerate internal network resources, probe internal services, or facilitate secondary attacks against backend systems that implicitly trust requests from the WebSphere server. While the direct impact is limited, chaining this vulnerability with others could contribute to broader compromise; a CSO Online report noted that multiple IBM WebSphere Liberty flaws can be chained into a full system takeover (CSO Online, IBM Advisory).
IBM has released a patch in WebSphere Application Server Liberty version 26.0.0.4, which resolves this vulnerability. Organizations should upgrade all affected Liberty instances to version 26.0.0.4 or later as the primary remediation. As interim measures, restrict network access to WebSphere servers, implement network segmentation to limit exposure to untrusted networks, and monitor for anomalous outbound HTTP requests originating from WebSphere Application Server processes. Downstream products (SPSS Collaboration and Deployment Services, IBM CICS TX Advanced, IBM License Metric Tool v9) have separate advisories with product-specific guidance (IBM Advisory, IBM CICS TX Advisory, IBM SPSS Advisory).
CSO Online reported that CVE-2026-1561 is one of seven IBM WebSphere Liberty flaws that can be chained together to achieve a full system takeover, elevating the practical risk beyond the individual CVSS score suggests (CSO Online). The Hacker News included the vulnerability in its weekly security recap, indicating moderate community awareness (The Hacker News). The Open Liberty project published a blog post accompanying the 26.0.0.4 release that addresses this and related fixes (Open Liberty Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."