Description
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.
Published: 2026-08-05
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM QRadar SIEM versions 7.6.0.0–7.6.0.1 and 7.5.0–7.5.0 UP 15 Interim Fix 005 contain an XML External Entity (XXE) injection flaw in the parseXmlPayload() function. Attacks allow a remote actor to send crafted XML data to the syslog intake on port 514 (UDP/TCP) without authentication. The vulnerability can lead to disclosure of sensitive configuration files or arbitrary local files, potentially compromising system integrity and confidentiality.

Affected Systems

All IBM QRadar SIEM installations running versions 7.5.x (including 7.5.0 through 7.5.0 UP15) and 7.6.x (7.6.0.0–7.6.0.1) are affected. Vendors advise applying the fixed releases: 7.6.0.2 and the 7.5.0 UP15 IF05 Hotfix (20260715231428) to mitigate the issue.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. EPSS data is unavailable, but the vulnerability is exploitable from the internet via the unprotected syslog port, and it is not currently listed in the CISA KEV catalog. Attackers would need to send malicious XML to the syslog service; no privileged credentials are required, making the risk accessible to remote attackers within network reach of port 514.

Generated by OpenCVE AI on August 5, 2026 at 17:37 UTC.

Remediation

Vendor Solution

IBM strongly encourages customers to update their systems promptly. ProductVersionFixIBM QRadar SIEM 7.6.0  7.6.0.2 https://www.ibm.com/support/pages/node/7280199 IBM QRadar SIEM 7.5.0  7.5.0 UP15 IF05 Hotfix 20260715231428 https://www.ibm.com/support/pages/node/7282364


OpenCVE Recommended Actions

  • Apply IBM’s official patch by upgrading to QRadar 7.6.0.2 or installing the 7.5.0 UP15 IF05 Hotfix (20260715231428).
  • If immediate patching is not possible, disable XML-format property autodetection in the event processing pipeline to stop automatic parsing of XML syslog events.
  • Limit or filter inbound traffic on syslog port 514 (UDP/TCP) to trusted IP ranges or enforce secure transport to reduce exposure to unauthenticated XML payloads.

Generated by OpenCVE AI on August 5, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.
Title IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability
First Time appeared Ibm
Ibm qradar
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:qradar:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar:7.5.0up15:interim_fix_005:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar:7.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar:7.6.0.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm qradar
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-05T16:03:19.008Z

Reserved: 2026-05-28T17:57:56.702Z

Link: CVE-2026-10025

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T17:30:07Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference