ZeroHour

CVE-2026-13287

moderate

XML External Entity Injection in IBM MQ Exposes Files, Enables Memory Exhaustion

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

IBM MQ versions spanning the 9.1 through 10.0 release trains contain an XML external entity (XXE) injection flaw (CWE-611) in the way the product processes XML data. A remote attacker with some level of valid access or privileges (the CVSS vector specifies PR:L) can submit crafted XML containing malicious external entity declarations, which IBM MQ resolves when parsing the data. Successful exploitation lets the attacker read sensitive information such as local files or internal resources, or repeatedly trigger entity expansion to consume memory resources and degrade or disrupt the queue manager (high confidentiality impact, low availability impact). Any organization running the listed IBM MQ LTS or Continuous Delivery (CD) versions — common in banking, finance, government, and other enterprise messaging backbones — is affected. The vulnerability is not in the CISA Known Exploited Vulnerabilities catalog, no public proof of concept exists, and no exploitation has been reported to date.

What to do: Apply the fix IBM has released for this CVE by upgrading affected queue managers beyond the listed end-point versions of each 9.1–10.0 LTS/CD stream, prioritizing internet-reachable and multi-tenant deployments. In the interim, restrict which authenticated users and applications can submit XML messages to MQ, and consider disabling or sandboxing DTD/external entity resolution in XML processing paths. Monitor queue manager logs and XML message flows for entities referencing local files or unusual recursive entity structures, which are telltale XXE probing signs.

Affected
IBM MQ9.1.0.0 - 9.1.0.37 LTS
IBM MQ9.2.0.0 - 9.2.0.43 LTS
IBM MQ9.3.0.0 - 9.3.0.41 LTS
IBM MQ9.3.0.0 - 9.3.5.1 CD
IBM MQ9.4.0.0 - 9.4.0.25 LTS
IBM MQ9.4.0.0 - 9.4.5.1 CD
IBM MQ10.0.0.0
Estimated exposure
moderateTens of thousands of enterprise IBM MQ instances worldwide; likely only low thousands directly internet-exposed — IBM MQ is deployed at thousands of large enterprises (heavily concentrated in banking and finance) but is primarily internal middleware, with public internet scans typically showing only a few thousand exposed MQ channel listeners on port…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.