
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8400 is a critical unsafe reflection vulnerability in the ORB (Object Request Broker) component of IBM SDK, Java Technology Edition, affecting IBM WebSphere Application Server (WAS) 8.5 and 9.0, as well as IBM WebSphere Application Server Liberty (Continuous Delivery). The flaw allows a malicious IIOP (Internet Inter-ORB Protocol) server to induce the loading and instantiation of arbitrary classes on the affected system. It was published on August 5, 2026, with IBM's advisory released as part of the July 2026 CPU update (IBM Advisory). The NVD assigns a CVSS v3.1 base score of 9.8 (Critical), while the GitHub Advisory Database and ENISA score it at 8.1 (High) due to differing attack complexity assessments (GitHub Advisory, IBM Advisory).
The root cause is classified as CWE-470 (Use of Externally-Controlled Input to Select Classes or Code — 'Unsafe Reflection'), where the ORB component in IBM SDK, Java Technology Edition fails to sufficiently validate or restrict class selection driven by external IIOP server responses (GitHub Advisory). An attacker operating a malicious IIOP server can craft responses that cause the vulnerable WAS instance to load and instantiate arbitrary Java classes, a technique analogous to deserialization or class injection attacks over the CORBA/IIOP protocol. Exploitation requires the target WAS instance to initiate or accept IIOP connections with an attacker-controlled server; no authentication or user interaction is required, though the attack complexity may be moderate depending on network positioning (IBM Advisory, Red Hat Bugzilla).
Successful exploitation enables an unauthenticated remote attacker to achieve arbitrary code execution on the affected WebSphere Application Server instance by forcing the JVM to load and instantiate attacker-chosen classes (IBM Advisory). This results in full compromise of confidentiality, integrity, and availability of the affected server, as confirmed by the CVSS metrics showing high impact across all three dimensions. Depending on the server's role and network position, exploitation could facilitate lateral movement within enterprise environments, access to sensitive application data, or disruption of business-critical services (GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (IBM Advisory). The EPSS score is approximately 0.44–0.48%, placing it around the 40th percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and the NVD SSVC assessment notes it is not currently automatable and has no known exploitation activity. No specific threat actor attribution has been reported.
SystemOut.log, SystemErr.log) showing unexpected class loading events, ClassNotFoundException, or ORB-related errors; Java security manager violations related to reflection or class instantiation.sh, bash, cmd.exe, powershell, curl, wget); unexpected network connections initiated by the WAS process.IBM has released patches as part of the July 2026 CPU update; administrators should apply the fix detailed in IBM Security Bulletin node/7282446 for WAS 8.5, 9.0, and Liberty Continuous Delivery (IBM Advisory). Red Hat has addressed the underlying java-1.8.0-ibm package vulnerability via RHSA-2026:52949 for Red Hat Enterprise Linux 8 (Red Hat Bugzilla). IBM also published additional advisories covering IBM Content Collector for SAP Applications (IBM SAP Advisory) and IBM AIX/PowerVM VIOS. As a workaround where patching is not immediately possible, restrict network access to IIOP ports using firewall rules, implement network segmentation to prevent WAS instances from connecting to untrusted IIOP servers, and disable IIOP if it is not required by the application.
The vulnerability received coverage from security aggregators and community platforms including VulnDB, Vulners, and CVEFeed shortly after publication (VulnDB). SUSE issued a security update (SUSE-SU-2026:3614-1) addressing the underlying IBM Java SDK flaw, and AusCERT published advisories (ESB-2026.9070, ESB-2026.9303, ESB-2026.9585) tracking the issue across affected IBM products. Social media discussion was limited, with brief mentions on Mastodon/infosec.exchange and Bluesky, reflecting standard community awareness without significant alarm given the absence of public exploits.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."