Impact
IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 contain an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. An attacker who can reach the application may exploit this weakness to access services without valid credentials, potentially allowing disclosure, tampering, or other privileged actions against the application. The weakness is a clear example of CWE‑306, a credential or authentication bypass flaw. The description does not explicitly state remote code execution, but the impact of unauthorized access could enable further exploitation within the affected environment.
Affected Systems
The vulnerability affects IBM WebSphere Application Server Liberty from version 17.0.0.3 up to 26.0.0.8 when the rtcomm‑1.0 or rtcommGateway‑1.0 features are enabled. Only installations using these features in the affected version range are impacted; other modules or newer releases are not mentioned as vulnerable.
Risk and Exploitability
The high CVSS score of 9.4 indicates a severe risk, with no EPSS score available and the vulnerability not listed in CISA’s KEV catalog. The likely attack vector involves accessing the application over a network, exploiting the enabled feature to bypass authentication. Because the flaw is a direct credential bypass, it can be used by an unauthenticated attacker to gain privileged access if adequate protections are not in place.
OpenCVE Enrichment