Skip to content
IBMCVE-2026-13265

IBM MQ: information disclosure

Medium6.8CVE-2026-13265 · Published Sep 14, 2026 · updated Sep 16, 2026

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API.

IBM advisory

Affected versions

PackageAffectedFixed in
MQ
Product
>= 9.1.0.0, <= 9.1.0.37 LTSNo fix yet
>= 9.2.0.0, <= 9.2.0.43 LTSNo fix yet
>= 9.3.0.0, <= 9.3.0.41 LTSNo fix yet
>= 9.3.0.0, <= 9.3.5.1 CDNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-611

More IBM advisories

All IBM
Advisory
IBM Business Automation Workflow containers and traditional: XML external entity
High7.1Sep 14
IBM Cloud Pak for Business Automation: missing authorization
Medium5.4Sep 14
IBM Cloud Pak for Business Automation: denial of service
Medium6.5Sep 14
IBM Langflow OSS: server-side request forgery
Critical9.6Sep 14
IBM Sterling Secure Proxy: improper authorization
Medium4.3Sep 14
IBM Sterling Secure Proxy: spoofing
Medium5.4Sep 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.