IBM WebSphere Liberty: Critical Auth Bypass, Privilege Escalation, DoS Disclosed Together
Key findings • Critical authentication bypass (CVE-2026-14525) in rtcomm features for IBM WebSphere Liberty. • High severity privilege escalation (CVE-2026-18499) possible in Liberty collecti…

Key findings
- Critical authentication bypass (CVE-2026-14525) in rtcomm features for IBM WebSphere Liberty.
- High severity privilege escalation (CVE-2026-18499) possible in Liberty collectives.
- Medium denial of service (CVE-2026-10571) via insecure deserialization in restConnector.
- Vulnerabilities affect IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8.
- Patches are available from IBM for all disclosed CVEs.
On August 12-13, 2026, a batch of three vulnerabilities was disclosed for IBM WebSphere Application Server Liberty. The most severe of these, CVE-2026-14525, is a critical authentication bypass flaw. The disclosures highlight potential security weaknesses in specific Liberty features and collective management.
CVE-2026-14525, rated Critical with a CVSSv3 score of 9.4, allows an attacker to bypass authentication when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. This could lead to unauthorized access to sensitive functionalities or data within the application server.
A separate high-severity vulnerability, CVE-2026-18499 (CVSSv3 8.1), affects Liberty collectives and can lead to privilege escalation. This means a user with limited access could potentially gain higher privileges within the collective environment.
Rounding out the batch is CVE-2026-10571, a medium-severity denial of service vulnerability (CVSSv3 5.7). This flaw occurs when the restConnector-2.0 feature is enabled and can be exploited by a low-privileged administrative user to consume system resources, potentially leading to service disruption.
All three vulnerabilities affect IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8. IBM has released fixes for these issues, and users are strongly advised to update to the latest available versions to mitigate these risks.
The coordinated disclosure of these vulnerabilities underscores the importance of regularly reviewing and securing the specific features and configurations enabled within WebSphere Application Server Liberty environments. Users should pay close attention to the enabled features, particularly rtcomm-1.0, rtcommGateway-1.0, and restConnector-2.0, as well as the security of Liberty collectives.
The batch of vulnerabilities includes:
- CVE-2026-14525: Critical authentication bypass in rtcomm features.
- CVE-2026-18499: High severity privilege escalation in Liberty collectives.
- CVE-2026-10571: Medium severity denial of service via insecure deserialization in restConnector.
All affected versions are 17.0.0.3 through 26.0.0.8. Patches are available from IBM.