CVE-2026-8400

Summary

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.

Affected Software

VendorProductVersion RangeStatus
IBMWebSphere Application Server8.5affected
IBMWebSphere Application Server9.0affected
IBMWebSphere Application Server - LibertyContinuous deliveryaffected

Weaknesses

  • CWE-470: CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References