SYS::ONLINE
Wasteland.
Briefs1594
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-14446 2026-07-28

IBM WebSphere Application Server: Critical Admin Console Access Control Flaw (CVE-2026-14446)

"IBM has disclosed a critical (CVSS 9.8) broken access control flaw in the WebSphere Application Server administrative console affecting versions 9.0 and 8.5."

IBM has disclosed a critical (CVSS 9.8) broken access control flaw in the WebSphere Application Server administrative console affecting versions 9.0 and 8.5.

What Is It

CVE-2026-14446 is a broken access control / privilege escalation vulnerability in the administrative console of IBM WebSphere Application Server. The flaw is categorized as CWE-306 (Missing Authentication for Critical Function). It was published on 2026-07-28 by IBM PSIRT, and currently carries NVD status "Received"; meaning the record has not yet completed NVD analysis.

Why It Matters

The CVSS 3.1 base score is 9.8 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Read plainly: the vulnerability is reachable over the network, requires low attack complexity, needs no privileges and no user interaction, and yields high impact to confidentiality, integrity, and availability. Exploitability scores 3.9, the maximum, and impact scores 5.9.

On the strength of that vector alone, the scenario the score describes is an unauthenticated remote attacker reaching the admin console and gaining substantial control over the application server. That is the metric's characterization rather than a demonstrated outcome: the score is vendor-supplied and still awaiting NVD analysis, no exploit or proof-of-concept has been published in the material available here, and how far an attacker actually gets will depend on deployment specifics; chiefly whether the console is exposed beyond a management network. What is not in doubt is why the target matters: WebSphere admin consoles control deployed applications and their credentials, so organizations should treat the console's network exposure as the variable worth checking first.

CVE-2026-14446 does not appear in the CISA Known Exploited Vulnerabilities catalog as of publication, so active exploitation is not confirmed at this time. The catalog is updated continuously; check it directly for the current status.

What's Vulnerable

Affected CPEs listed by IBM:

Patch Status

The single reference supplied is IBM's support bulletin at node 7281631, published by IBM PSIRT ([email protected]). No specific fix pack versions, remediation steps, or required-action deadlines are included in the source material provided here; consult the IBM bulletin directly for available patches. Because the CVE is not listed in the CISA KEV catalog, no federal remediation due date applies to it under BOD 22-01.

Sources