CVE-2026-13275
moderateXXE in IBM MQ Managed File Transfer Allows Authenticated File Read and SSRF
IBM MQ Managed File Transfer contains an XML external entity injection (XXE, CWE-611) flaw in its reply message processing, affecting releases from 9.1 through 10.0.0.0 across the LTS and CD streams. An authenticated attacker can send a crafted XML reply message containing malicious external entity definitions; when the MFT component parses it, the referenced entities are resolved, allowing the attacker to read arbitrary files on the server or issue server-side requests to internal resources (SSRF). Successful exploitation requires valid MQ credentials (attack complexity low, privileges low), and the flaw carries a CVSS 3.1 base score of 7.1 (high), with high confidentiality impact and low integrity impact. Organizations running IBM MQ with the Managed File Transfer capability enabled in any of the listed version ranges are affected. There is no known public proof of concept and the CVE is not on the CISA KEV list, indicating no confirmed in-the-wild exploitation at this time.
What to do: Apply IBM's fixed fix packs or releases for your stream (9.1, 9.2, 9.3 LTS/CD, 9.4 LTS/CD, or 10.0) as specified in the IBM advisory, prioritizing any MFT-enabled queue managers reachable by less-trusted users. Restrict which authenticated principals can submit MFT transfer/reply messages, and review MQ and host logs for anomalous reply messages, unexpected local file access, or outbound connections from the MQ server consistent with SSRF probing.
| IBM MQ Managed File Transfer | 9.1.0.0 through 9.1.0.37 LTS |
| IBM MQ Managed File Transfer | 9.2.0.0 through 9.2.0.43 LTS |
| IBM MQ Managed File Transfer | 9.3.0.0 through 9.3.0.41 LTS |
| IBM MQ Managed File Transfer | 9.3.0.0 through 9.3.5.1 CD |
| IBM MQ Managed File Transfer | 9.4.0.0 through 9.4.0.25 LTS |
| IBM MQ Managed File Transfer | 9.4.0.0 through 9.4.5.1 CD |
| IBM MQ Managed File Transfer | 10.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery due to XML external entity injection in reply message processing.
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.