Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API.
Published: 2026-09-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: XML External Entity injection in the MQ Managed File Transfer REST API can expose sensitive data or cause service disruption by an authenticated attacker with MFT publish authority
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an XML External Entity (XEE) injection flaw in the IBM MQ web Managed File Transfer REST API. An attacker who authenticates with MFT publish authority can provide a crafted XML payload that triggers the resolution of an external entity. This can lead the server to read arbitrary files or transmit sensitive configuration details, or it can exhaust system resources, resulting in a denial of service. The flaw is categorized as CWE‑611.

Affected Systems

IBM MQ 9.1 LTS versions 9.1.0.0 through 9.1.0.37, IBM MQ 9.2 LTS versions 9.2.0.0 through 9.2.0.43, IBM MQ 9.3 LTS versions 9.3.0.0 through 9.3.0.41 and 9.3.5.1 CD, IBM MQ 9.4 LTS versions 9.4.0.0 through 9.4.0.25 and 9.4.5.1 CD, and IBM MQ 10.0.0.0. Each of these releases includes a cumulative security update that addresses the flaw.

Risk and Exploitability

The vulnerability has a CVSS score of 6.8, indicating a moderate level of severity. Its EPSS score is reported as < 1%, indicating a very low likelihood of exploitation; the flaw is not listed in the CISA KEV catalog. Exploitation requires that the attacker obtain authenticated access with MFT publish authority, which limits the threat window but still represents a non‑negligible risk for organizations running the affected MQ versions.

Generated by OpenCVE AI on September 17, 2026 at 19:18 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT474594 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the cumulative security update 9.1.0.38 to IBM MQ 9.1.0.0‑9.1.0.37 LTS
  • Apply the cumulative security update 9.2.0.44 to IBM MQ 9.2.0.0‑9.2.0.43 LTS
  • Apply the cumulative security update 9.3.0.42 to IBM MQ 9.3.0.0‑9.3.0.41 LTS
  • Apply the cumulative security update 9.4.0.26 to IBM MQ 9.4.0.0‑9.4.0.25 LTS
  • Upgrade IBM MQ 9.3.5.1 CD, 9.4.5.1 CD, and 10.0.0.0 to IBM MQ 10.0.0.5 or newer

Generated by OpenCVE AI on September 17, 2026 at 19:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API.
Title IBM MQ Managed File Transfer REST API is vulnerable to XML external entity injection
First Time appeared Ibm
Ibm mq
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:46.459Z

Reserved: 2026-06-24T21:12:02.885Z

Link: CVE-2026-13265

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:39.790Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T22:16:57.100

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-13265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference