Skip to main content

IBM WebSphere Application Server Unauthenticated SSRF via SIP Container Enables Internal Network Compromise (CVE-2026-14529)

Scope: IBM WebSphere Application Server Traditional 8.5 and 9.0 / WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.8 (with SIP Container Feature Enabled)

Severity: Red

A critical server-side request forgery vulnerability (CVSS 9.4) in IBM WebSphere Application Server stems from missing authentication on the SIP container feature (sipServlet-1.1), allowing unauthenticated remote attackers to craft malicious requests that appear to originate from within the internal network, bypassing firewalls, network segmentation, and IP-based access controls to probe backend services, access internal systems, and exfiltrate sensitive data. IBM has confirmed both Traditional and Liberty deployment models are affected, making this a broad risk across enterprise environments where WebSphere is a foundational middleware component for banking, government, and ERP integrations. Organizations must immediately assess whether the SIP container feature is enabled via the WebSphere admin console, disable it if not operationally required, and apply interim fix PH72053 for Liberty or DT495928 for Traditional while upgrading to the targeted Fix Packs 26.0.0.9, 9.0.5.29, or 8.5.5.31 expected in Q3 2026.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.