XML External Entity Injection in IBM MQ Affecting Multiple Versions
CVE-2026-13275
7.1HIGH
What is CVE-2026-13275?
An XML external entity injection vulnerability in IBM MQ allows an authenticated attacker to read arbitrary files on the server or perform server-side request forgery. This issue manifests during the processing of reply messages, impacting several versions and potentially compromising the security of sensitive data.
Affected Version(s)
MQ 9.1.0.0 <= 9.1.0.37 LTS
MQ 9.2.0.0 <= 9.2.0.43 LTS
MQ 9.3.0.0 <= 9.3.0.41 LTS