Junglewise Threat Intelligence

CVE-2026-18499: IBM WebSphere Application Server Liberty privilege escalation in collectives

CVE-2026-18499 · Severity: high · CVSS 8.1 · Published 2026-08-12

Technologies: IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server Liberty is an application platform that enterprises use to host and run business-critical Java applications. When Liberty's collective features (collectiveController or collectiveMember) are enabled, an authenticated attacker with low privileges can escalate their access to gain high-level permissions, potentially leading to unauthorized control over the application server and its hosted applications.

Technical details

This is an improper authorization vulnerability (CWE-285) affecting the collective controller and member features in Liberty. An authenticated attacker (PR:L) can exploit this over the network (AV:N) without additional user interaction (UI:N) to escalate privileges and gain high-impact access to confidentiality and integrity of the system. The vulnerability requires the collectiveController-1.0 or collectiveMember-1.0 feature to be explicitly enabled. IBM recommends upgrading to Liberty Fix Pack 26.0.0.9 or later (targeted availability Q3 2026), or applying the interim fix for APAR DT497580.

Affected products

  • IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8

Timeline

  • 2026-08-12: disclosed

References

Related threats