---
id: CVE-2026-13759
title: >-
  IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three
  ObjectInputStream subclasses (WsObjectInputStream,
  ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install
  no JEP-290 class filter; when Coherence is o…
summary: >-
  IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three
  ObjectInputStream subclasses (WsObjectInputStream,
  ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install
  no JEP-290 class filter; when Coherence is o…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: ibm
product: websphere_extreme_scale
affected:
  - 'websphere_extreme_scale >= 8.6.1.0, <= 8.6.1.6'
published: '2026-06-30'
updated: '2026-07-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13759'
references:
  - url: 'https://www.ibm.com/support/pages/node/7278595'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00546
epssPercentile: 0.43324
ingestedAt: '2026-07-03T20:53:53.298Z'
---

## Overview

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including RemoteConstructor.readResolve and PriorityQueue/ExtractorComparator are confirmed working, allowing a post-login attacker who can write a session attribute or a LAN-adjacent attacker on the grid replication wire to execute arbitrary code on peer WAS JVMs

## Affected

- `websphere_extreme_scale >= 8.6.1.0, <= 8.6.1.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
