Skip to content
IBMCVE-2026-12666

IBM MQ: information disclosure

High8.1CVE-2026-12666 · Published Sep 15, 2026 · updated Sep 17, 2026

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Classes for Java could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to XML external entity injection in MQRFH2 header processing.

IBM advisory

Affected versions

PackageAffectedFixed in
MQ
Product
>= 9.1.0.0, <= 9.1.0.37 LTSNo fix yet
>= 9.2.0.0, <= 9.2.0.43 LTSNo fix yet
>= 9.3.0.0, <= 9.3.0.41 LTSNo fix yet
>= 9.3.0.0, <= 9.3.5.1 CDNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-611

More IBM advisories

All IBM
Advisory
IBM Cloud Pak for Business Automation: cross-site scripting
Medium5.4Sep 15
IBM Business Automation Workflow containers and traditional: XML external entity
High7.1Sep 15
IBM Security Verify Access: denial of service
High7.5Sep 15
IBM MQ: denial of service
High7.1Sep 15
IBM MQ: code execution
High8.8Sep 15
IBM Business Automation Workflow: missing authorization
Medium5.4Sep 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.