XML External Entity Injection Vulnerability in IBM MQ
CVE-2026-13287
7.1HIGH
What is CVE-2026-13287?
IBM MQ contains a vulnerability that allows attackers to perform XML external entity injection. This occurs when the application processes XML data containing external references, potentially enabling remote attackers to access sensitive information or deplete system resources. It is crucial for organizations using affected versions of IBM MQ to implement patches and safeguard their systems against unauthorized access.
Affected Version(s)
MQ 9.1.0.0 <= 9.1.0.37 LTS
MQ 9.2.0.0 <= 9.2.0.43 LTS
MQ 9.3.0.0 <= 9.3.0.41 LTS