CVE-2026-13773: IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used as Transport Protocol
Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.stringtoobject() on an
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.6.2.* - Configuration
Do not use Object Request Broker (ORB) as the transport protocol; configure eXtreme Scale to use IBM eXtremeIO (XIO) as the transport protocol so the SSRF via ORB is not applicable.
WebSphere eXtreme Scale Transport protocol = IBM eXtremeIO (XIO)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13773?
CVE-2026-13773 has a medium severity rating of 6.
What type of vulnerability is CVE-2026-13773?
CVE-2026-13773 is classified as a server-side request forgery (SSRF) vulnerability.
Which software is affected by CVE-2026-13773?
CVE-2026-13773 affects IBM WebSphere eXtreme Scale versions 8.6.1.0 through 8.6.1.6.
How do I mitigate CVE-2026-13773?
Mitigation for CVE-2026-13773 involves upgrading to a patched version of IBM WebSphere eXtreme Scale.
What are the potential impacts of CVE-2026-13773?
CVE-2026-13773 could allow an attacker to perform unauthorized actions on internal services.