PT-2026-53942 · Ibm · Ibm Websphere Application Server+1

CVE-2026-13759

·

Published

2026-06-30

·

Updated

2026-07-03

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6
Description Three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, and ObjectInputStreamResolver) do not install a JEP-290 class filter, which is a mechanism used to filter incoming serialized data to prevent the instantiation of unauthorized classes. When Coherence is present on the classpath, multiple remote code execution gadget chains, such as RemoteConstructor.readResolve and PriorityQueue/ExtractorComparator, can be utilized. This allows an attacker who has already logged in and can write a session attribute, or an attacker located on the local area network (LAN) adjacent to the grid replication wire, to execute arbitrary code on peer WebSphere Application Server (WAS) Java Virtual Machines (JVMs).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13759

Affected Products

Ibm Websphere Application Server
Ibm Websphere Extreme Scale