CVE-2026-13759

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including RemoteConstructor.readResolve and PriorityQueue/ExtractorComparator are confirmed working, allowing a post-login attacker who can write a session attribute or a LAN-adjacent attacker on the grid replication wire to execute arbitrary code on peer WAS JVMs
References
Link Resource
https://www.ibm.com/support/pages/node/7278595 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:websphere_extreme_scale:*:*:*:*:*:*:*:*

History

02 Jul 2026, 18:43

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:websphere_extreme_scale:*:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7278595 - () https://www.ibm.com/support/pages/node/7278595 - Vendor Advisory
First Time Ibm
Ibm websphere Extreme Scale

30 Jun 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-30 20:17

Updated : 2026-07-03 04:17


NVD link : CVE-2026-13759

Mitre link : CVE-2026-13759

CVE.ORG link : CVE-2026-13759


JSON object : View

Products Affected

ibm

  • websphere_extreme_scale
CWE
CWE-502

Deserialization of Untrusted Data