Executive brief
IBM WebSphere Application Server Liberty, a platform for building and running Java applications, contains a security flaw that could allow an attacker to bypass security protections. By exploiting a specific timing window, an attacker could gain unauthorized access to sensitive information. This vulnerability only affects systems with specific application security features enabled and requires high privileges to exploit.
Technical details
A security bypass vulnerability exists in IBM WebSphere Application Server Liberty versions 22.0.0.11 through 26.0.0.5 when the appSecurity-3.0, appSecurity-4.0, or appSecurity-5.0 features are enabled. The flaw is rooted in a race condition or timing window that can be exploited by a remote attacker with high privileges. Successful exploitation allows the attacker to bypass security controls and potentially access sensitive data. The vulnerability is tracked via APAR PH70798 and is addressed in Liberty Fix Pack 26.0.0.6 or via interim fixes for affected versions.
Affected products
- IBM WebSphere Application Server Liberty 22.0.0.11 through 26.0.0.5
Timeline
- 2026-05-19: advisory: Initial publication by IBM
- 2026-05-27: disclosed: NVD publication date