CVE-2026-10571: CWE-502 Deserialization of Untrusted Data in IBM WebSphere Application Server - Liberty
IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 contain a vulnerability involving insecure deserialization that can be exploited by a low-privileged administrative user to cause a denial of service when the restConnector-2.0 feature is enabled. This vulnerability does not impact confidentiality or integrity but can disrupt availability by consuming system resources.
AI Analysis
Technical Summary
CVE-2026-10571 is a medium severity vulnerability in IBM WebSphere Application Server - Liberty affecting versions 17.0.0.3 through 26.0.0.8. It arises from insecure deserialization (CWE-502) that allows a low-privileged administrative user to trigger a denial of service condition by exhausting system resources when the restConnector-2.0 feature is enabled. The vulnerability has a CVSS 3.1 base score of 5.7, reflecting its network attack vector, low attack complexity, and required privileges. No confidentiality or integrity impact is noted.
Potential Impact
An attacker with low-privileged administrative access can exploit this vulnerability to cause a denial of service, impacting system availability by consuming resources. There is no impact on confidentiality or integrity. The vulnerability requires the restConnector-2.0 feature to be enabled to be exploitable.
Mitigation Recommendations
Patch status is not yet confirmed — check the IBM vendor advisory for current remediation guidance. Until a fix is available, consider disabling the restConnector-2.0 feature if it is not required, or restrict administrative user access to trusted personnel to reduce risk.
CVE-2026-10571: CWE-502 Deserialization of Untrusted Data in IBM WebSphere Application Server - Liberty
Description
IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 contain a vulnerability involving insecure deserialization that can be exploited by a low-privileged administrative user to cause a denial of service when the restConnector-2.0 feature is enabled. This vulnerability does not impact confidentiality or integrity but can disrupt availability by consuming system resources.
CVSS v3.1
Score 5.7medium
Affected software
IBM
WebSphere Application Server - Liberty
pkg:maven/com.ibm.websphere/websphere-application-server-libertycpe:2.3:a:ibm:websphere_application_server_liberty:17.0.0.3:*:*:*:*:*:*:*cpe:2.3:a:ibm:websphere_application_server_liberty:26.0.0.8:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-10571 is a medium severity vulnerability in IBM WebSphere Application Server - Liberty affecting versions 17.0.0.3 through 26.0.0.8. It arises from insecure deserialization (CWE-502) that allows a low-privileged administrative user to trigger a denial of service condition by exhausting system resources when the restConnector-2.0 feature is enabled. The vulnerability has a CVSS 3.1 base score of 5.7, reflecting its network attack vector, low attack complexity, and required privileges. No confidentiality or integrity impact is noted.
Potential Impact
An attacker with low-privileged administrative access can exploit this vulnerability to cause a denial of service, impacting system availability by consuming resources. There is no impact on confidentiality or integrity. The vulnerability requires the restConnector-2.0 feature to be enabled to be exploitable.
Mitigation Recommendations
Patch status is not yet confirmed — check the IBM vendor advisory for current remediation guidance. Until a fix is available, consider disabling the restConnector-2.0 feature if it is not required, or restrict administrative user access to trusted personnel to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- ibm
- Date Reserved
- 2026-06-01T16:53:37.814Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7e217bbf8831d539ba0cc9
Added to database: 08/13/2026, 19:56:43 UTC
Last enriched: 08/21/2026, 13:28:58 UTC
Last updated: 09/28/2026, 13:47:42 UTC
Views: 55
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.