Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery due to XML external entity injection in reply message processing.
Published: 2026-09-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Server‑side request forgery and file disclosure
Action: Immediate Patch
AI Analysis

Impact

IBM MQ clients that process reply messages are vulnerable to XML external entity injection, which allows an attacker with authenticated access to the Managed File Transfer service to read arbitrary files on the server or to trigger server‑side requests to arbitrary URLs, thereby compromising confidentiality and potentially enabling further lateral movement.

Affected Systems

The vulnerability affects IBM MQ versions 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS and 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS and 9.4.5.1 CD, as well as version 10.0.0.0 of the Managed File Transfer component. These releases are listed under the IBM MQ product line.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high‑severity vulnerability. The EPSS score is 0.251%, indicating a very low probability of exploitation, but the absence of a KEV listing suggests no widely publicized exploitation at this time. Based on the description, the attack vector is likely internal or network‑based, requiring authenticated access to the MFT server; an attacker would submit a crafted XML payload that causes the server to resolve external entity references.

Generated by OpenCVE AI on September 17, 2026 at 19:18 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT474689 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Upgrade IBM MQ to the cumulative security updates: 9.1.0.38 for 9.1 LTS, 9.2.0.44 for 9.2 LTS, 9.3.0.42 for 9.3 LTS, 9.4.0.26 for 9.4 LTS, and 10.0.0.5 for 10.0.0.0, following the links in the vendor’s advisory.
  • If an upgrade is not immediately possible, modify the MFT XML parser configuration to disable external entity processing or restrict allowed external entities, thereby blocking XML external entity injection attempts.
  • Apply strict access controls so that only trusted users can invoke Managed File Transfer operations, and isolate the MFT service from untrusted network segments.

Generated by OpenCVE AI on September 17, 2026 at 19:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery due to XML external entity injection in reply message processing.
Title IBM MQ Managed File Transfer is vulnerable to XML external entity injection
First Time appeared Ibm
Ibm mq
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T18:03:54.340Z

Reserved: 2026-06-24T21:37:58.586Z

Link: CVE-2026-13275

cve-icon Vulnrichment

Updated: 2026-09-15T17:38:34.695Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:01.393

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-13275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference