Privilege Escalation in IBM WebSphere Liberty 17.0.0.3-26.0.0.8
CVE-2026-18499 Published on August 12, 2026
IBM WebSphere Application Server Liberty is affected by a privilege escalation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.
Vulnerability Analysis
CVE-2026-18499 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-18499 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-18499
Want to know whenever a new CVE is published for IBM Websphere Application Server Liberty? stack.watch will email you.
Affected Versions
IBM WebSphere Application Server - Liberty:- Version 17.0.0.3, <= 26.0.0.8 is affected.