CVE-2026-8400
Received Received - Intake

IBM WebSphere ORB Class Loading Vulnerability

Vulnerability report for CVE-2026-8400, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: IBM Corporation

Description

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
ibm websphere_application_server to 9.0 (inc)
ibm websphere_application_server_liberty continuous_delivery
ibm websphere_application_server 8.5
ibm websphere_application_server 9.0
ibm websphere_application_server_liberty *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-470 The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-8400 is a flaw in the ORB component of IBM SDK, Java Technology Edition, affecting IBM WebSphere Application Server and Liberty. A malicious IIOP server could exploit this to load and instantiate arbitrary classes, potentially leading to unauthorized access or data manipulation.

Impact Analysis

This vulnerability could allow attackers to execute arbitrary code, gain unauthorized access to systems, manipulate data, or cause denial of service. It may compromise the confidentiality, integrity, and availability of affected applications and data.

Compliance Impact

This vulnerability could lead to data breaches, unauthorized access, or data manipulation, which may violate compliance requirements such as GDPR (data protection) and HIPAA (health information security). Organizations must address it to maintain regulatory compliance.

Mitigation Strategies

Upgrade to IBM SDK, Java Technology Edition Version 8 SR8 FP70 or apply interim fixes as recommended by IBM. Affected versions include WebSphere Application Server 8.5, 9.0, and Liberty.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8400. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart