Junglewise Threat Intelligence

CVE-2026-12118: IBM webMethods Integration remote code execution in WmServiceMock

CVE-2026-12118 · Severity: critical · CVSS 9.8 · Published 2026-07-30

Executive brief

IBM webMethods Integration, a platform used for connecting different software applications and data sources, contains a critical security flaw in a bundled testing utility. An unauthenticated attacker could remotely take full control of the server by sending specially crafted data. This vulnerability exists in a development tool that should not be present on production or internet-facing systems. Exploitation could lead to a total compromise of the server, including unauthorized access to sensitive business data and the ability to disrupt operations.

Technical details

A critical deserialization of untrusted data vulnerability (CWE-502) exists in the WmServiceMock package bundled with IBM webMethods Integration Server versions 10.15 and 10.11. The WmServiceMock package, intended as a development-time testing utility, does not implement its own authentication mechanism and relies on the Integration Server's settings. An unauthenticated remote attacker can exploit this by sending malicious serialized objects to the server, resulting in arbitrary code execution with the privileges of the Integration Server process. IBM has stated that no software patch is required; instead, the remediation is to manually delete the WmServiceMock package from all production and internet-facing nodes.

Affected products

  • IBM webMethods Integration (on prem) 10.15, 10.11

Timeline

  • 2026-07-02: disclosed: Initial publication by IBM
  • 2026-07-30: advisory: NVD publication date

References

Related threats