CVE-2026-8400
IBM JDK vulnerability analysis and mitigation

Overview

CVE-2026-8400 is a critical unsafe reflection vulnerability in the ORB (Object Request Broker) component of IBM SDK, Java Technology Edition, affecting IBM WebSphere Application Server (WAS) 8.5 and 9.0, as well as IBM WebSphere Application Server Liberty (Continuous Delivery). The flaw allows a malicious IIOP (Internet Inter-ORB Protocol) server to induce the loading and instantiation of arbitrary classes on the affected system. It was published on August 5, 2026, with IBM's advisory released as part of the July 2026 CPU update (IBM Advisory). The NVD assigns a CVSS v3.1 base score of 9.8 (Critical), while the GitHub Advisory Database and ENISA score it at 8.1 (High) due to differing attack complexity assessments (GitHub Advisory, IBM Advisory).

Technical details

The root cause is classified as CWE-470 (Use of Externally-Controlled Input to Select Classes or Code — 'Unsafe Reflection'), where the ORB component in IBM SDK, Java Technology Edition fails to sufficiently validate or restrict class selection driven by external IIOP server responses (GitHub Advisory). An attacker operating a malicious IIOP server can craft responses that cause the vulnerable WAS instance to load and instantiate arbitrary Java classes, a technique analogous to deserialization or class injection attacks over the CORBA/IIOP protocol. Exploitation requires the target WAS instance to initiate or accept IIOP connections with an attacker-controlled server; no authentication or user interaction is required, though the attack complexity may be moderate depending on network positioning (IBM Advisory, Red Hat Bugzilla).

Impact

Successful exploitation enables an unauthenticated remote attacker to achieve arbitrary code execution on the affected WebSphere Application Server instance by forcing the JVM to load and instantiate attacker-chosen classes (IBM Advisory). This results in full compromise of confidentiality, integrity, and availability of the affected server, as confirmed by the CVSS metrics showing high impact across all three dimensions. Depending on the server's role and network position, exploitation could facilitate lateral movement within enterprise environments, access to sensitive application data, or disruption of business-critical services (GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (IBM Advisory). The EPSS score is approximately 0.44–0.48%, placing it around the 40th percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and the NVD SSVC assessment notes it is not currently automatable and has no known exploitation activity. No specific threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify IBM WebSphere Application Server 8.5 or 9.0 instances (or Liberty Continuous Delivery) exposed on the network, particularly those with IIOP ports open (default TCP 2809 or configured IIOP listener ports), using network scanning tools such as Nmap or Shodan.
  2. Set up malicious IIOP server: Deploy a rogue CORBA/IIOP server that is crafted to return malicious object references or class descriptors designed to trigger arbitrary class loading in the IBM JDK ORB component.
  3. Induce IIOP connection: Cause the target WAS instance to connect to the malicious IIOP server — this may be achieved by exploiting application-level functionality that performs IIOP lookups, or by intercepting/redirecting legitimate IIOP traffic via a man-in-the-middle position.
  4. Trigger class loading: The malicious IIOP server responds with crafted protocol messages that exploit the unsafe reflection flaw in the ORB component, causing the WAS JVM to load and instantiate an attacker-specified class from the classpath or a remote codebase.
  5. Achieve code execution: The instantiated class executes attacker-controlled logic within the JVM process context, enabling arbitrary command execution, reverse shell establishment, or further post-exploitation activity (IBM Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Network: Unexpected outbound IIOP/CORBA connections (TCP port 2809 or other configured IIOP ports) from WebSphere server processes to unknown or external IP addresses; unusual inbound IIOP traffic from untrusted sources.
  • Logs: WebSphere system logs (SystemOut.log, SystemErr.log) showing unexpected class loading events, ClassNotFoundException, or ORB-related errors; Java security manager violations related to reflection or class instantiation.
  • Process: Unusual child processes spawned by the WebSphere JVM (e.g., sh, bash, cmd.exe, powershell, curl, wget); unexpected network connections initiated by the WAS process.
  • File System: New or modified files in the WebSphere installation directory or temp directories; unexpected JAR files or class files appearing in the application server's classpath locations.

Mitigation and workarounds

IBM has released patches as part of the July 2026 CPU update; administrators should apply the fix detailed in IBM Security Bulletin node/7282446 for WAS 8.5, 9.0, and Liberty Continuous Delivery (IBM Advisory). Red Hat has addressed the underlying java-1.8.0-ibm package vulnerability via RHSA-2026:52949 for Red Hat Enterprise Linux 8 (Red Hat Bugzilla). IBM also published additional advisories covering IBM Content Collector for SAP Applications (IBM SAP Advisory) and IBM AIX/PowerVM VIOS. As a workaround where patching is not immediately possible, restrict network access to IIOP ports using firewall rules, implement network segmentation to prevent WAS instances from connecting to untrusted IIOP servers, and disable IIOP if it is not required by the application.

Community reactions

The vulnerability received coverage from security aggregators and community platforms including VulnDB, Vulners, and CVEFeed shortly after publication (VulnDB). SUSE issued a security update (SUSE-SU-2026:3614-1) addressing the underlying IBM Java SDK flaw, and AusCERT published advisories (ESB-2026.9070, ESB-2026.9303, ESB-2026.9585) tracking the issue across affected IBM products. Social media discussion was limited, with brief mentions on Mastodon/infosec.exchange and Bluesky, reflecting standard community awareness without significant alarm given the absence of public exploits.

Additional resources


SourceThis report was generated using AI

Related IBM JDK vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8400CRITICAL9.8
  • IBM JDK logoIBM JDK
  • java-1.8.0-ibm-demo
NoYesAug 05, 2026
CVE-2026-61308MEDIUM6.8
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.7.0-openjdk.src
NoYesAug 18, 2026
CVE-2026-60147MEDIUM6.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-25-openjdk-headless-slowdebug
NoYesJul 21, 2026
CVE-2026-70907MEDIUM5.3
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • openjdk-17
NoYesAug 18, 2026
CVE-2026-60589LOW3.7
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-21-openjdk-headless-debuginfo
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management