CVE-2026-8400
Received
Received - Intake
IBM WebSphere ORB Class Loading Vulnerability
Vulnerability report for CVE-2026-8400, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-05
Last updated on: 2026-08-05
Assigner: IBM Corporation
Description
Description
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | websphere_application_server | to 9.0 (inc) |
| ibm | websphere_application_server_liberty | continuous_delivery |
| ibm | websphere_application_server | 8.5 |
| ibm | websphere_application_server | 9.0 |
| ibm | websphere_application_server_liberty | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-470 | The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code. |