IBMCVE-2026-13265
IBM MQ: information disclosure
Medium6.8CVE-2026-13265 · Published Sep 14, 2026 · updated Sep 16, 2026
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| MQ Product | >= 9.1.0.0, <= 9.1.0.37 LTS | No fix yet |
| >= 9.2.0.0, <= 9.2.0.43 LTS | No fix yet | |
| >= 9.3.0.0, <= 9.3.0.41 LTS | No fix yet | |
| >= 9.3.0.0, <= 9.3.5.1 CD | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-611
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 14 | IBM Business Automation Workflow containers and traditional: XML external entity | High7.1 | No fix yet |
| Sep 14 | IBM Cloud Pak for Business Automation: missing authorization | Medium5.4 | No fix yet |
| Sep 14 | IBM Cloud Pak for Business Automation: denial of service | Medium6.5 | No fix yet |
| Sep 14 | IBM Langflow OSS: server-side request forgery | Critical9.6 | No fix yet |
| Sep 14 | IBM Sterling Secure Proxy: improper authorization | Medium4.3 | No fix yet |
| Sep 14 | IBM Sterling Secure Proxy: spoofing | Medium5.4 | No fix yet |