File Read and Limited DoS Vulnerability in IBM MQ by IBM
CVE-2026-12667
7.1HIGH
What is CVE-2026-12667?
IBM MQ versions 9.1.0.0 through 10.0.0.0 are susceptible to an XML External Entity (XXE) flaw that allows an authenticated attacker to read sensitive files from a vulnerable .NET client. This vulnerability arises from improper handling of XML external entities during RFH2 folder parsing. Additionally, it can result in a limited denial of service, potentially disrupting service availability. Organizations using impacted versions should prioritize applying security updates to protect against these risks.
Affected Version(s)
MQ 9.1.0.0 <= 9.1.0.37 LTS
MQ 9.2.0.0 <= 9.2.0.43 LTS
MQ 9.3.0.0 <= 9.3.0.41 LTS