CVE-2026-13287
moderateXML External Entity Injection in IBM MQ Exposes Files, Enables Memory Exhaustion
IBM MQ versions spanning the 9.1 through 10.0 release trains contain an XML external entity (XXE) injection flaw (CWE-611) in the way the product processes XML data. A remote attacker with some level of valid access or privileges (the CVSS vector specifies PR:L) can submit crafted XML containing malicious external entity declarations, which IBM MQ resolves when parsing the data. Successful exploitation lets the attacker read sensitive information such as local files or internal resources, or repeatedly trigger entity expansion to consume memory resources and degrade or disrupt the queue manager (high confidentiality impact, low availability impact). Any organization running the listed IBM MQ LTS or Continuous Delivery (CD) versions — common in banking, finance, government, and other enterprise messaging backbones — is affected. The vulnerability is not in the CISA Known Exploited Vulnerabilities catalog, no public proof of concept exists, and no exploitation has been reported to date.
What to do: Apply the fix IBM has released for this CVE by upgrading affected queue managers beyond the listed end-point versions of each 9.1–10.0 LTS/CD stream, prioritizing internet-reachable and multi-tenant deployments. In the interim, restrict which authenticated users and applications can submit XML messages to MQ, and consider disabling or sandboxing DTD/external entity resolution in XML processing paths. Monitor queue manager logs and XML message flows for entities referencing local files or unusual recursive entity structures, which are telltale XXE probing signs.
| IBM MQ | 9.1.0.0 - 9.1.0.37 LTS |
| IBM MQ | 9.2.0.0 - 9.2.0.43 LTS |
| IBM MQ | 9.3.0.0 - 9.3.0.41 LTS |
| IBM MQ | 9.3.0.0 - 9.3.5.1 CD |
| IBM MQ | 9.4.0.0 - 9.4.0.25 LTS |
| IBM MQ | 9.4.0.0 - 9.4.5.1 CD |
| IBM MQ | 10.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.