ZeroHour

CVE-2026-13275

moderate

XXE in IBM MQ Managed File Transfer Allows Authenticated File Read and SSRF

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

IBM MQ Managed File Transfer contains an XML external entity injection (XXE, CWE-611) flaw in its reply message processing, affecting releases from 9.1 through 10.0.0.0 across the LTS and CD streams. An authenticated attacker can send a crafted XML reply message containing malicious external entity definitions; when the MFT component parses it, the referenced entities are resolved, allowing the attacker to read arbitrary files on the server or issue server-side requests to internal resources (SSRF). Successful exploitation requires valid MQ credentials (attack complexity low, privileges low), and the flaw carries a CVSS 3.1 base score of 7.1 (high), with high confidentiality impact and low integrity impact. Organizations running IBM MQ with the Managed File Transfer capability enabled in any of the listed version ranges are affected. There is no known public proof of concept and the CVE is not on the CISA KEV list, indicating no confirmed in-the-wild exploitation at this time.

What to do: Apply IBM's fixed fix packs or releases for your stream (9.1, 9.2, 9.3 LTS/CD, 9.4 LTS/CD, or 10.0) as specified in the IBM advisory, prioritizing any MFT-enabled queue managers reachable by less-trusted users. Restrict which authenticated principals can submit MFT transfer/reply messages, and review MQ and host logs for anomalous reply messages, unexpected local file access, or outbound connections from the MQ server consistent with SSRF probing.

Affected
IBM MQ Managed File Transfer9.1.0.0 through 9.1.0.37 LTS
IBM MQ Managed File Transfer9.2.0.0 through 9.2.0.43 LTS
IBM MQ Managed File Transfer9.3.0.0 through 9.3.0.41 LTS
IBM MQ Managed File Transfer9.3.0.0 through 9.3.5.1 CD
IBM MQ Managed File Transfer9.4.0.0 through 9.4.0.25 LTS
IBM MQ Managed File Transfer9.4.0.0 through 9.4.5.1 CD
IBM MQ Managed File Transfer10.0.0.0
Estimated exposure
moderate≈ thousands to tens of thousands of enterprise MQ/MFT installations (exact MFT-enabled count unknown) — IBM MQ is pervasive in banking and enterprise messaging (public internet scans show tens of thousands of MQ listeners on port 1414), but Managed File Transfer is an optional component and exploitation requires authentication, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery due to XML external entity injection in reply message processing.

Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.