CVE-2026-13285
moderateXXE Injection in IBM MQ Exposes Sensitive Data and Enables Memory Exhaustion
IBM MQ versions spanning the 9.1 LTS through 10.0.0.0 streams are vulnerable to XML external entity (XXE) injection when processing XML data, tracked as CVE-2026-13285 (CVSS 3.1: 7.1 high). An attacker with some level of authorized access (the CVSS vector requires low privileges) who can submit crafted XML to the message broker triggers parsing of malicious external entity definitions. Successful exploitation lets the attacker read sensitive local files or reach internal network resources, disclosing highly confidential information, and can also exhaust memory to degrade or crash the service. Virtually the entire supported IBM MQ estate across LTS and Continuous Delivery streams is affected, so organizations running any 9.1–10.0 deployment should treat this as high priority. No public proof-of-concept exists and there is no indication of exploitation in the wild, and the flaw is not on the CISA KEV list.
What to do: Apply IBM's fix packs to every affected MQ 9.1–10.0 queue manager and any components that parse XML messages, following the remediation versions in IBM's security bulletin. In the interim, restrict which authenticated users and applications can put XML-formatted messages on queues, disable external DTD/entity resolution in XML processing where supported, and audit MQ servers for evidence of file-read or SSRF-style outbound connections to unexpected internal addresses.
| IBM MQ | 9.1.0.0 through 9.1.0.37 LTS |
| IBM MQ | 9.2.0.0 through 9.2.0.43 LTS |
| IBM MQ | 9.3.0.0 through 9.3.0.41 LTS |
| IBM MQ | 9.3.0.0 through 9.3.5.1 CD |
| IBM MQ | 9.4.0.0 through 9.4.0.25 LTS |
| IBM MQ | 9.4.0.0 through 9.4.5.1 CD |
| IBM MQ | 10.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.