Skip to content
IBMCVE-2026-13477

IBM QRadar: code execution

Medium4.7CVE-2026-13477 · Published Aug 5, 2026 · updated Aug 10, 2026

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.

IBM advisory

Affected versions

PackageAffectedFixed in
QRadar
Product
>= 7.6.0.0, <= 7.6.0.1No fix yet
>= 7.5.0, <= 7.5.0 UP 15 Interim Fix 005No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-78

More IBM advisories

All IBM
Advisory
IBM Langflow OSS: weak cryptography
High7.4Aug 5
IBM Langflow OSS: code injection
High8.1Aug 5
IBM Langflow OSS: code execution
High8.8Aug 5
IBM Langflow OSS: information disclosure
High7.1Aug 5
IBM Langflow OSS: code injection
High8.8Aug 5
IBM Langflow OSS: broken cryptography
High7.4Aug 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.