Vulnerability in IBM WebSphere Extreme Scale Class Handling
CVE-2026-13772

7.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 June 2026

What is CVE-2026-13772?

The Object Query Language engine in IBM WebSphere Extreme Scale versions 8.6.1.0 to 8.6.1.6 is susceptible to a significant vulnerability. Attackers with authenticated remote access can influence OQL query strings, leading to execution of arbitrary constructors on the WebSphere Application Server JVM. This risk persists through various methods, including SELECT DISTINCT queries, which may allow malicious payloads to traverse grid node boundaries despite serialization filters, thereby exposing the application to potential exploitation.

Affected Version(s)

WebSphere Extreme Scale 8.6.1.0 <= 8.6.1.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.