<Vulnerability name="CVE-2026-8400">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-04T00:00:00</PublicDate>
    <Bugzilla id="2512497" url="https://bugzilla.redhat.com/show_bug.cgi?id=2512497" xml:lang="en:us">
java-1.8.0-ibm: Arbitrary class loading and instantiation via malicious IIOP server
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>8.1</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-470</CWE>
    <Details xml:lang="en:us" source="Mitre">
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the ORB (Object Request Broker) component of IBM SDK, Java Technology Edition. A malicious IIOP (Internet Inter-ORB Protocol) server could exploit this vulnerability to force the loading and creation of unauthorized software components. This could lead to the execution of arbitrary code, potentially compromising the affected system.
    </Details>
    <Mitigation xml:lang="en:us">
To mitigate this issue, ensure that applications are configured to only connect to trusted IIOP servers. Restrict network access to prevent connections to untrusted or external IIOP endpoints.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:8::supplementary">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-08-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:52949">RHSA-2026:52949</Advisory>
        <Package name="java-1.8.0-ibm">java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10</Package>
    </AffectedRelease>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-8400
https://nvd.nist.gov/vuln/detail/CVE-2026-8400
https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBM_Security_Update_July_2026
https://www.ibm.com/support/pages/node/7282446
    </References>
</Vulnerability>