PT-2026-53942 · Ibm · Ibm Websphere Application Server+1
CVE-2026-13759
·
Published
2026-06-30
·
Updated
2026-07-03
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6
Description
Three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, and ObjectInputStreamResolver) do not install a JEP-290 class filter, which is a mechanism used to filter incoming serialized data to prevent the instantiation of unauthorized classes. When Coherence is present on the classpath, multiple remote code execution gadget chains, such as RemoteConstructor.readResolve and PriorityQueue/ExtractorComparator, can be utilized. This allows an attacker who has already logged in and can write a session attribute, or an attacker located on the local area network (LAN) adjacent to the grid replication wire, to execute arbitrary code on peer WebSphere Application Server (WAS) Java Virtual Machines (JVMs).
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Websphere Application Server
Ibm Websphere Extreme Scale