CVE-2026-14525: IBM WebSphere Application Server Liberty is affected by an authenication bypass
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.9 - Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Patch DT496165 - Compensating control
Verify whether rtcomm-1.0 or rtcommGateway-1.0 features are enabled in IBM WebSphere Application Server Liberty (refer to IBM support page “How to determine if Liberty is using a specific feature” / node 6553910), and only apply the interim fix/fix pack after identifying feature usage.