CVE-2026-18499 – IBM WebSphere Application Server – Liberty

CVSS 8.1 IMPORTANT Critical - Same Day Deployment

“Authentication and privilege-control failures can expose vulnerable Liberty environments to unauthorized access and elevated privileges.”

IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 are affected by two vulnerabilities. CVE-2026-14525 is an authentication bypass affecting systems where the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. CVE-2026-14525 has a CVSS score of 9.4, Critical severity.

CVE-2026-18499 affects environments using Liberty collectives and can enable privilege escalation. CVE-2026-18499 has a CVSS score of 8.1, High severity.

Key Details

Affected Product
Ibm Websphere Application Server
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-285
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.