Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-13773: IBM WebSphere Extreme Scale CORBA Stub Classes SSRF

CVE-2026-13773
Summary

IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6 have a security issue that allows an attacker to trick the system into making unauthorized connections to other servers. This could potentially lead to the attacker gaining control of the system. To fix this, update to a newer version of WebSphere Extreme Scale that is not affected by this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ibm websphere_extreme_scale >= 8.6.1.0, <= 8.6.1.6
cpe:2.3:a:ibm:websphere_extreme_scale:*:*:*:*:*:*:*:*
Original title
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR...
Original description
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an attacker-chosen host; when chained with the IBM ORB's getUserException class-instantiation flaw (WAS-26), this SSRF escalates to remote code execution on the calling JVM.
nvd CVSS3.1 6.0
Vulnerability type
CWE-918 Server-Side Request Forgery (SSRF)
Published: 30 Jun 2026 · Updated: 23 Jul 2026 · First seen: 30 Jun 2026