Authentication Vulnerability in IBM QRadar by IBM
CVE-2026-5522

6.7MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-5522?

The vulnerability in IBM QRadar stems from the presence of hard-coded credentials, including passwords and cryptographic keys. These credentials are utilized for inbound authentication, facilitate outbound communication with external components, and handle the encryption of sensitive internal data. This poses a risk as unauthorized access to these credentials could allow malicious actors to exploit the system, compromising the security and integrity of user data and system operations. It is essential for organizations using affected versions of IBM QRadar to apply patches and follow best security practices to mitigate potential threats.

Affected Version(s)

QRadar 7.5.0 <= 7.5.0 UP15 Interim Fix 005

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.