CVE-2026-2310
moderateXXE Injection in IBM webMethods Integration Server 11.1
IBM webMethods Integration Server 11.1 is vulnerable to XML external entity (XXE) injection (CWE-91) when it processes XML data, allowing an attacker to have the server's XML parser resolve malicious external entity references. According to IBM, a remote attacker can trigger the flaw by submitting crafted XML to the server; the CVSS vector (AV:L/AC:L/PR:L) indicates low-privileged access is required, consistent with an attacker who can get XML to the parser. A successful exploit can expose sensitive information handled by the server (e.g., files or internal resources reachable by the parser) or consume memory resources, causing a denial-of-service condition. The flaw affects organizations running IBM webMethods Integration Server 11.1, an enterprise integration middleware product typically deployed inside corporate data centers. As of now the flaw is not in CISA's Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.
What to do: Check IBM's PSIRT advisory for CVE-2026-2310 and apply the IBM-provided fix for webMethods Integration Server 11.1 as soon as it is published; no fixed version is specified in the available data. Until then, review whether any 11.1 instances accept XML from lower-privileged or untrusted sources, and mitigate by disabling external entity/DTD resolution in the XML parser and restricting the server's outbound network access to limit file-disclosure and memory-exhaustion impact.
| IBM webMethods Integration Server | 11.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
- Weakness
- CWE-91
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.