CVE-2026-14525: IBM WebSphere Application Server Liberty is affected by an authenication bypass
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.9Patch DT496165 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch DT496165 - Configuration
If rtcomm-1.0 or rtcommGateway-1.0 is enabled on Liberty, disable those features until the interim fix/fix pack that resolves APAR DT496165 is applied (vulnerable when either feature is enabled).
IBM WebSphere Application Server Liberty rtcomm-1.0 / rtcommGateway-1.0 feature = disable - Operational
Verify whether rtcomm-1.0 or rtcommGateway-1.0 features are enabled in IBM WebSphere Application Server Liberty before and after applying the interim fix/fix pack (see IBM page 'How to determine if Liberty is using a specific feature').
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14525?
The severity of CVE-2026-14525 is critical, with a CVSS score of 9.4.
How do I fix CVE-2026-14525?
To fix CVE-2026-14525, ensure that the rtcomm-1.0 or rtcommGateway-1.0 feature is disabled in IBM WebSphere Application Server Liberty.
What versions of IBM WebSphere Application Server Liberty are affected by CVE-2026-14525?
IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 are affected by CVE-2026-14525.
What type of vulnerability is CVE-2026-14525?
CVE-2026-14525 is classified as an authentication bypass vulnerability.
What impact does CVE-2026-14525 have on the security of my application?
CVE-2026-14525 allows unauthorized access to the application, potentially compromising sensitive data.