IBM WebSphere Liberty Auth Bypass (rtcomm/rtcommGateway) 17.0.0.3-26.0.0.8
CVE-2026-14525 Published on August 13, 2026

IBM WebSphere Application Server Liberty is affected by an authenication bypass
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-14525 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and a small impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
LOW

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2026-14525

Want to know whenever a new CVE is published for IBM Websphere Application Server Liberty? stack.watch will email you.

 

Affected Versions

IBM WebSphere Application Server - Liberty: