XML External Entity Injection Vulnerability in IBM MQ
CVE-2026-13287

7.1HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-13287?

IBM MQ contains a vulnerability that allows attackers to perform XML external entity injection. This occurs when the application processes XML data containing external references, potentially enabling remote attackers to access sensitive information or deplete system resources. It is crucial for organizations using affected versions of IBM MQ to implement patches and safeguard their systems against unauthorized access.

Affected Version(s)

MQ 9.1.0.0 <= 9.1.0.37 LTS

MQ 9.2.0.0 <= 9.2.0.43 LTS

MQ 9.3.0.0 <= 9.3.0.41 LTS

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.