Summary
CVE-2026-14525 is a critical authentication bypass vulnerability (CWE-306: Missing Authentication for Critical Function) affecting IBM WebSphere Application Server Liberty. The flaw is present when the rtcomm-1.0 or rtcommGateway-1.0 Real-Time Communications features are enabled, and it carries a CVSS v3.1 base score of 9.4 (Critical).
Technical details
- Root cause: missing authentication enforcement for a critical function within Liberty’s Real-Time Communications components.
- Trigger condition: the vulnerability only applies to Liberty instances that have the
rtcomm-1.0orrtcommGateway-1.0feature enabled. - Attack vector: network-based, no privileges and no user interaction required, low attack complexity.
- Impact: high confidentiality impact, high integrity impact, low availability impact — consistent with an unauthenticated attacker gaining access to functionality that should require authentication.
Affected software
- IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 (when the
rtcomm-1.0orrtcommGateway-1.0feature is enabled).
Severity
- CVSS v3.1 Base Score: 9.4 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Mitigation and recommended actions
- Immediate: Apply the interim fix for APAR DT496165, or upgrade to WebSphere Application Server Liberty Fix Pack 26.0.0.9 or later once available (targeted 3Q2026).
- If no patch can be applied immediately: Identify whether the
rtcomm-1.0orrtcommGateway-1.0features are enabled in your Liberty server configuration; if they are not required, disable them to remove the exposure until the fix can be applied.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
WebSphere Liberty(with or without a trailing version number)

