CVE-2026-18527 affects IBM Application Runtime Expert (ARE) for i version 1R1M0. The vulnerability exists in the ARE GUI component and allows a remote, unauthenticated attacker to gain elevated privileges on the IBM i system. By exploiting this flaw, an attacker can execute actions under another authenticated user's profile without needing their own credentials. This represents a significant security risk as it enables unauthorized privilege escalation on IBM i systems. IBM has published a support advisory detailing the issue. The vulnerability is rated High severity given the unauthenticated remote exploitation potential and the ability to compromise user sessions and system integrity.