Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to read files from a vulnerable .NET client or cause limited denial of service due to improper handling of XML external entities in RFH2 folder parsing.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: File disclosure
Action: Patch Now
AI Analysis

Impact

The vulnerability is an XML external entity injection flaw in IBM MQ’s .NET client. When a client processes a crafted XML document, the parser may resolve external entities, enabling an attacker to read files stored on the client machine or to trigger a limited denial‑of‑service condition. The weakness is identified as CWE‑611.

Affected Systems

The flaw affects IBM MQ .NET clients in versions 9.1.0.0 through 9.1.0.37, 9.2.0.0 through 9.2.0.43, 9.3.0.0 through 9.3.0.41, 9.3.0.0 through 9.3.5.1 in the CD distribution, 9.4.0.0 through 9.4.0.25, 9.4.0.0 through 9.4.5.1 in the CD distribution, and 10.0.0.0. IBM publishes cumulative security updates that address this issue: 9.1.0.38 for 9.1 LTS, 9.2.0.44 for 9.2 LTS, 9.3.0.42 for 9.3 LTS and the 9.3 CD releases, 9.4.0.26 for 9.4 LTS and the 9.4 CD releases, and version 10.0.0.5 for the 10.0.0.0 release.

Risk and Exploitability

With a CVSS score of 7.1 the flaw is considered high severity. The EPSS score of less than 1% indicates a very low probability of exploitation and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation to date. The likely attack path involves an authenticated .NET client that receives or sends a malicious XML document; the client's XML parser then resolves external entities to access files on the client machine or to cause a limited denial of service. Based on the description, it is inferred that an attacker must first authenticate to the MQ system and then supply a crafted XML payload to the client for the flaw to be triggered.

Generated by OpenCVE AI on September 20, 2026 at 15:37 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT474690 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the IBM MQ cumulative security update 9.1.0.38 to all IBM MQ 9.1 LTS installations.
  • Apply the IBM MQ cumulative security update 9.2.0.44 to all IBM MQ 9.2 LTS installations.
  • Apply the IBM MQ cumulative security update 9.3.0.42 to all IBM MQ 9.3 LTS installations and the 9.3 CD releases.
  • Apply the IBM MQ cumulative security update 9.4.0.26 to all IBM MQ 9.4 LTS installations and the 9.4 CD releases.
  • Upgrade any IBM MQ 10.0.0.0 deployments to version 10.0.0.5 to remediate the flaw.
  • Restrict network access so that only authenticated .NET clients with validated credentials can connect to the MQ server, limiting exposure to the vulnerability.

Generated by OpenCVE AI on September 20, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to read files from a vulnerable .NET client or cause limited denial of service due to improper handling of XML external entities in RFH2 folder parsing.
Title IBM MQ .NET client is vulnerable to XML external entity injection
First Time appeared Ibm
Ibm mq
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T19:00:37.702Z

Reserved: 2026-06-18T20:29:30.669Z

Link: CVE-2026-12667

cve-icon Vulnrichment

Updated: 2026-09-15T19:00:32.912Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:14.420

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-12667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:45:17Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference