IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 contain a critical authentication bypass reachable over the network when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
What Is It
CVE-2026-14525 is an authentication bypass in IBM WebSphere Application Server - Liberty, classified as CWE-306 (Missing Authentication for Critical Function). The flaw is exposed when either the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled in the server configuration. IBM's PSIRT assigned a CVSS 3.1 base score of 9.4 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L.
The CVE was published on 2026-08-13 and is currently in "Awaiting Analysis" status at NVD.
Why It Matters
The CVSS vector describes about the worst reachability profile available: network attack vector, low attack complexity, no privileges required, and no user interaction. That yields a maximum exploitability subscore of 3.9. Impact is high to both confidentiality and integrity, with low availability impact.
In practical terms, anyone who can reach an affected Liberty instance with the rtcomm features enabled can bypass authentication without credentials or user interaction. There is no CISA KEV entry for this CVE, so active exploitation is not confirmed at this time, but the low bar to exploitation makes it a priority for anyone running the affected feature set.
What's Vulnerable
- Vendor: IBM
- Product: WebSphere Application Server - Liberty
- Affected versions: 17.0.0.3 through 26.0.0.8 (inclusive)
- Precondition: the
rtcomm-1.0orrtcommGateway-1.0feature must be enabled
Installations that do not enable either rtcomm feature are outside the stated condition for the vulnerability.
Patch Status
IBM has published a security bulletin at IBM support node 7283488, which is the sole vendor reference in the NVD record. Consult that bulletin for fix levels and remediation steps. No CISA KEV required-action date applies, as this CVE is not listed in the Known Exploited Vulnerabilities catalog. Administrators should review whether rtcomm-1.0 or rtcommGateway-1.0 is enabled and treat that as the primary triage question.
Sources
- NVD, CVE-2026-14525: https://nvd.nist.gov/vuln/detail/CVE-2026-14525
- IBM Security Bulletin ([email protected]): https://www.ibm.com/support/pages/node/7283488