Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Classes for Java could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to XML external entity injection in MQRFH2 header processing.
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data disclosure or denial of service
Action: Apply Patch
AI Analysis

Impact

IBM MQ processes MQRFH2 headers that contain XML. In affected versions the XML parser does not properly restrict external entity resolution, allowing an authenticated attacker to embed external entity references and cause the server to dereference local files or network resources. This can lead to sensitive information disclosure or trigger a denial‑of‑service if the input is malformed.

Affected Systems

Affected products are IBM MQ across multiple LTS and CDN releases. The vulnerability exists in IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CDN, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CDN, and in the 10.0.0.0 Java classes. IBM recommends applying the cumulative security update appropriate for each version (for example 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, or 10.0.0.5).

Risk and Exploitability

The CVSS score of 8.1 indicates high impact, and the EPSS score is 0.00264, indicating a very low exploitation probability, but the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authentication with the message broker, the attack vector is likely over an authenticated network session to IBM MQ. The risk remains high for environments that expose MQ services to internal attackers or misconfigured clients, and remediation through patching is imperative.

Generated by OpenCVE AI on September 20, 2026 at 15:10 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT474364 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Download and install the IBM MQ cumulative security update that corresponds to your current version (e.g., 9.1.0.38 for IBM MQ 9.1 LTS).
  • Restart the IBM MQ broker so that the updated classes load.
  • If a patch cannot be applied immediately, restrict usage of MQRFH2 headers in client applications or disable external entity processing until the update is deployed.

Generated by OpenCVE AI on September 20, 2026 at 15:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Classes for Java could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to XML external entity injection in MQRFH2 header processing.
Title IBM MQ Java messaging is vulnerable to XML external entity injection
First Time appeared Ibm
Ibm mq
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-17T16:22:00.550Z

Reserved: 2026-06-18T19:13:47.535Z

Link: CVE-2026-12666

cve-icon Vulnrichment

Updated: 2026-09-17T16:21:55.741Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:14.290

Modified: 2026-09-17T17:16:38.630

Link: CVE-2026-12666

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:15:17Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference