Skip to content
Threat Feed
high advisory

IBM WebSphere Application Server ORB Unsafe Reflection Vulnerability

A vulnerability in the Object Request Broker (ORB) component of IBM SDK for Java allows an unauthenticated attacker to trigger remote code execution via arbitrary class instantiation.

IBM WebSphere Application Server versions 8.5, 9.0, and the Liberty Continuous Delivery release contain a critical vulnerability in the Object Request Broker (ORB) component of the integrated IBM SDK, Java Technology Edition. Tracked as CVE-2026-8400, the flaw is classified under CWE-470 (Use of Externally-Controlled Input to Select Classes or Code). This vulnerability stems from unsafe reflection practices within the ORB's handling of IIOP (Internet Inter-ORB Protocol) traffic. An attacker operating a malicious IIOP server can send specially crafted requests to a vulnerable WebSphere instance, inducing the application to load and instantiate arbitrary classes. This primitive effectively allows for remote code execution, as the attacker can manipulate the application environment to execute arbitrary code or bypass security controls. Defenders should prioritize patching, as this vulnerability carries a CVSS 3.1 base score of 8.1.

Impact

Successful exploitation allows for unauthenticated remote code execution on affected WebSphere Application Server instances. This impact potentially grants an attacker full control over the application server process, enabling data exfiltration, service disruption, or further lateral movement within the network. This affects enterprise organizations utilizing IBM WebSphere for critical Java-based business applications.

Recommendation

Prioritize the application of official security patches from IBM for WebSphere Application Server and the associated IBM SDK for Java Technology Edition. Consult the IBM security bulletin at https://www.ibm.com/support/pages/node/7282446 for specific fix levels. As an immediate measure, restrict network access to the IIOP port (typically 2809) to trusted management segments only.


Immediate actions

Patch IBM WebSphere Application Server per IBM bulletin node 7282446

IT Operations 72h

Mitigations

Restrict network access to IIOP ports to known-good management IP ranges

immediate Network Security

CVE-2026-8400