
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18499 is a privilege escalation vulnerability in IBM WebSphere Application Server - Liberty affecting versions 17.0.0.3 through 26.0.0.8 when using Liberty collectives. The flaw was published on August 12, 2026, and is classified as High severity with a CVSS v3.1 base score of 8.1 (GitHub Advisory, IBM Support). The vulnerability allows an authenticated low-privilege user to escalate their permissions within the Liberty collective environment (GitHub Advisory).
The root cause is classified as CWE-285 (Improper Authorization), meaning the application does not correctly perform authorization checks when an actor attempts to access resources or perform actions within Liberty collectives (GitHub Advisory). The attack vector is network-based, requires low privileges, low attack complexity, and no user interaction, making it exploitable by any authenticated user with a basic account in a Liberty collective deployment. The vulnerability is specifically scoped to the Liberty collectives feature — a management topology that allows multiple Liberty servers to be administered as a group — and does not affect standalone Liberty instances that do not use this feature (IBM Support). No public proof-of-concept code has been identified at this time.
Successful exploitation allows an authenticated low-privilege user to escalate their permissions to gain high-level access within the Liberty collective environment, resulting in high confidentiality and high integrity impact with no availability impact (GitHub Advisory). An attacker could read sensitive configuration data, access protected resources, and modify system configurations across the collective, potentially affecting all member servers managed by the collective controller. This could facilitate lateral movement within the collective infrastructure and expose sensitive application data or credentials stored in the collective configuration.
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code at this time (GitHub Advisory). The EPSS score is approximately 0.27% (19th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for authenticated access (IBM Support). Detection support is available via Nessus plugin ID 335002.
IBM has released a fix in WebSphere Application Server - Liberty version 26.0.0.9, which resolves this vulnerability; administrators should upgrade from any affected version (17.0.0.3 through 26.0.0.8) to 26.0.0.9 or later (IBM Support). As interim workarounds, restrict network-level access to Liberty collective management ports to trusted administrators only, review and audit user roles and permissions within existing Liberty collective deployments, and monitor for suspicious privilege escalation attempts or unauthorized access to collective management functions. Organizations not using the Liberty collectives feature may consider disabling it to reduce attack surface.
The vulnerability received brief coverage from security aggregators and community feeds shortly after disclosure, including mentions on Mastodon via RedPacketSecurity and listings on VulDB and Vulners. AUSCERT published a bulletin (ESB-2026.9481) referencing the advisory, and IT Jungle covered it as part of a broader IBM security patch roundup on August 17, 2026. No significant independent researcher commentary or vendor statements beyond IBM's official advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."