CVE-2026-13265

medium

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API.

References

https://www.ibm.com/support/pages/node/7284895

Details

Source: Mitre, NVD

Published: 2026-09-14

Updated: 2026-09-16

Risk Information

CVSS v2

Base Score: 6.6

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 6.8

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00223