CVE-2026-10571

MEDIUM CVSS 3.1: 5.3 EPSS 0.56%
Updated Aug 17, 2026
IBM
Parameter Value
CVSS 5.3 (MEDIUM)
Affected Versions 17.0.0.3 — 26.0.0.9
Fixed In 26.0.0.9
Type CWE-502 (Deserialization of Untrusted Data)
Vendor IBM
Public PoC No

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 7

Configuration From (including) Up to (excluding)
Ibm Websphere_Application_Server
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:*
17.0.0.3 26.0.0.9
Apple Macos
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Ibm Aix
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
Ibm I
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
Ibm Z\/Os
cpe:2.3:o:ibm:z\/os:-:*:*:*:*:*:*:*
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Microsoft Windows
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*