CVE-2026-13773 MEDIUM

CVE-2026-13773: IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used as Transport Protocol

Vendor Ibm
Product WebSphere Extreme Scale
Weakness CWE-918 · SSRF
Published June 30, 2026
Last update June 30, 2026

CVSS base score

6.0/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an attacker-chosen host; when chained with the IBM ORB's getUserException class-instantiation flaw (WAS-26), this SSRF escalates to remote code execution on the calling JVM.

Key dates

02Disclosure timeline

June 30, 2026 CVE published

Related vulnerabilities

04Related CVE