PT-2026-53944 · Ibm · Ibm Websphere Application Server+1

CVE-2026-13773

·

Published

2026-06-30

·

Updated

2026-07-03

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6
Description Approximately 50 CORBA stub classes within the ogclient.jar file call the ORB.string to object() function using an attacker-controlled IOR string during Java deserialization. This allows an unfiltered ObjectInputStream sink in WebSphere Application Server to be used for outbound IIOP Server-Side Request Forgery (SSRF) to a host chosen by the attacker. When combined with a class-instantiation flaw in the IBM ORB getUserException function, this SSRF can be escalated to remote code execution on the calling JVM.
Recommendations Update IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6 to a patched version.

Fix

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13773

Affected Products

Ibm Websphere Application Server
Ibm Websphere Extreme Scale