A vulnerability categorized as critical has been discovered in IBM WebSphere Application Server up to 26.0.0.8. This issue affects some unknown processing of the component Liberty collectives. Such manipulation leads to improper privilege management.

This vulnerability is documented as CVE-2026-18499. The attack can be executed remotely. There is not any exploit available.