Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to read files from a vulnerable .NET client or cause limited denial of service due to improper handling of XML external entities in RFH2 folder parsing.
Published: 2026-09-15
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: File disclosure
Action: Apply patch
AI Analysis

Impact

IBM MQ’s .NET client contains a XML External Entity injection flaw in its RFH2 folder parsing logic. When a client supplies crafted XML, the parser can resolve external entities, allowing an authenticated attacker to read arbitrary files from the client machine or trigger a limited denial of service by manipulating the parsing routine. This weakness maps to CWE‑611 and requires the attacker to have valid MQ credentials to exploit.

Affected Systems

The vulnerability affects IBM MQ .NET client versions 9.1.0.0 through 9.1.0.37, 9.2.0.0 through 9.2.0.43, 9.3.0.0 through 9.3.0.41, 9.3.0.0 through 9.3.5.1 in the CD distribution, 9.4.0.0 through 9.4.0.25, 9.4.0.0 through 9.4.5.1 in the CD distribution, and 10.0.0.0. IBM publishes cumulative security updates that address this issue: 9.1.0.38 for 9.1 LTS, 9.2.0.44 for 9.2 LTS, 9.3.0.42 for 9.3 LTS, 9.4.0.26 for 9.4 LTS, and the 10.0.0.5 upgrade for the 10.0.0.0 release.

Risk and Exploitability

With a CVSS score of 7.1, the flaw is considered high severity. Exploitation requires an authenticated network connection to the MQ server and the use of the desktop .NET client; it does not provide remote code execution. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation yet. The attack path would involve the attacker sending malicious XML over the network to the client, triggering the vulnerable parser and consequently reading files or causing a limited denial of service.

Generated by OpenCVE AI on September 15, 2026 at 23:54 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT474690 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the IBM MQ cumulative security update 9.1.0.38 for all IBM MQ 9.1 LTS installations.
  • Apply the IBM MQ cumulative security update 9.2.0.44 for all IBM MQ 9.2 LTS installations.
  • Apply the IBM MQ cumulative security update 9.3.0.42 for all IBM MQ 9.3 LTS installations and the 9.3 CD releases.
  • Apply the IBM MQ cumulative security update 9.4.0.26 for all IBM MQ 9.4 LTS installations and the 9.4 CD releases.
  • Upgrade any IBM MQ 10.0.0.0 deployments to version 10.0.0.5 to remediate the flaw.
  • Ensure that only authenticated .NET clients with validated credentials can connect to the MQ server and consider restricting network access to the client environment to limit exposure.

Generated by OpenCVE AI on September 15, 2026 at 23:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to read files from a vulnerable .NET client or cause limited denial of service due to improper handling of XML external entities in RFH2 folder parsing.
Title IBM MQ .NET client is vulnerable to XML external entity injection
First Time appeared Ibm
Ibm mq
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T19:00:37.702Z

Reserved: 2026-06-18T20:29:30.669Z

Link: CVE-2026-12667

cve-icon Vulnrichment

Updated: 2026-09-15T19:00:32.912Z

cve-icon NVD

Status : Received

Published: 2026-09-15T18:17:14.420

Modified: 2026-09-15T19:17:15.613

Link: CVE-2026-12667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T00:00:16Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference