SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-14525 2026-08-13

IBM WebSphere Application Server Liberty Authentication Bypass

"IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 contain a critical authentication bypass reachable over the network when the `rtcomm-1.0` or `rtcommGateway-1.0` feature is enabled."

IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 contain a critical authentication bypass reachable over the network when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.

What Is It

CVE-2026-14525 is an authentication bypass in IBM WebSphere Application Server - Liberty, classified as CWE-306 (Missing Authentication for Critical Function). The flaw is exposed when either the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled in the server configuration. IBM's PSIRT assigned a CVSS 3.1 base score of 9.4 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L.

The CVE was published on 2026-08-13 and is currently in "Awaiting Analysis" status at NVD.

Why It Matters

The CVSS vector describes about the worst reachability profile available: network attack vector, low attack complexity, no privileges required, and no user interaction. That yields a maximum exploitability subscore of 3.9. Impact is high to both confidentiality and integrity, with low availability impact.

In practical terms, anyone who can reach an affected Liberty instance with the rtcomm features enabled can bypass authentication without credentials or user interaction. There is no CISA KEV entry for this CVE, so active exploitation is not confirmed at this time, but the low bar to exploitation makes it a priority for anyone running the affected feature set.

What's Vulnerable

Installations that do not enable either rtcomm feature are outside the stated condition for the vulnerability.

Patch Status

IBM has published a security bulletin at IBM support node 7283488, which is the sole vendor reference in the NVD record. Consult that bulletin for fix levels and remediation steps. No CISA KEV required-action date applies, as this CVE is not listed in the Known Exploited Vulnerabilities catalog. Administrators should review whether rtcomm-1.0 or rtcommGateway-1.0 is enabled and treat that as the primary triage question.

Sources