Vulnerability in IBM WebSphere Extreme Scale Class Handling
CVE-2026-13772
7.5HIGH
What is CVE-2026-13772?
The Object Query Language engine in IBM WebSphere Extreme Scale versions 8.6.1.0 to 8.6.1.6 is susceptible to a significant vulnerability. Attackers with authenticated remote access can influence OQL query strings, leading to execution of arbitrary constructors on the WebSphere Application Server JVM. This risk persists through various methods, including SELECT DISTINCT queries, which may allow malicious payloads to traverse grid node boundaries despite serialization filters, thereby exposing the application to potential exploitation.
Affected Version(s)
WebSphere Extreme Scale 8.6.1.0 <= 8.6.1.6