CVE-2026-8400 Details
Description
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
A vulnerability exists in the ORB component of the IBM SDK, Java Technology Edition, used in IBM WebSphere Application Server versions 8.5, 9.0, and IBM WebSphere Application Server - Liberty Continuous Delivery. This vulnerability may allow a malicious IIOP server to induce the loading and instantiation of arbitrary classes.
Users of IBM WebSphere Application Server Liberty should upgrade to IBM SDK, Java Technology Edition Version 8 SR8 FP70. For Version 9 of IBM WebSphere Application Server traditional, update to IBM SDK, Java Technology Edition, Version 8 Service Refresh 8 FP70. Users of IBM WebSphere Application Server traditional versions 8.5.0.0 through 8.5.5.30 should upgrade to the minimum fix pack level noted in the interim fix guidance and then apply the necessary interim fixes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7282446 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-470 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm websphere application server | 8.5.0.0 9.0.0.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | Initial Analysis | [email protected] |
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |