CVE-2026-18499 – IBM WebSphere Application Server – Liberty
CVSS 8.1
IMPORTANT
Critical - Same Day Deployment
“Authentication and privilege-control failures can expose vulnerable Liberty environments to unauthorized access and elevated privileges.”
IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 are affected by two vulnerabilities. CVE-2026-14525 is an authentication bypass affecting systems where the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. CVE-2026-14525 has a CVSS score of 9.4, Critical severity.
CVE-2026-18499 affects environments using Liberty collectives and can enable privilege escalation. CVE-2026-18499 has a CVSS score of 8.1, High severity.
Key Details
- Affected Product
- Ibm Websphere Application Server
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-285
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.