Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Published: 2026-09-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information disclosure and resource exhaustion via XML external entity injection
Action: Apply patches
AI Analysis

Impact

IBM MQ versions 9.1.0.0 through 9.1.0.37, 9.2.0.0 through 9.2.0.43, 9.3.0.0 through 9.3.0.41, 9.3.0.0 through 9.3.5.1, 9.4.0.0 through 9.4.0.25, 9.4.0.0 through 9.4.5..0 process XML data without properly disabling external entities, exposing them to a remote attacker. The vulnerability is a classic XML external entity (XXE) flaw (CWE-611) that can lead to the exfiltration of confidential files or data and can also cause excessive memory consumption or denial of service if a malicious XML document is submitted.

Affected Systems

All IBM MQ products, including IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.4 LTS, and IBM MQ 10.0.0, are vulnerable in the versions listed above. The specific impacted versions are those with major releases from 9.1.0.0 to 9.4.5.1 and the initial release of 10.0.0.0.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating a moderate to high risk. The EPSS score is 0.00385 (≈0.4%), showing a very low but non-zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker can remotely submit malicious XML, for example in application requests or messages passed through MQ, to trigger the XXE vulnerability. No known public exploit requires special prerequisites beyond having network access to the MQ environment that processes XML data.

Generated by OpenCVE AI on September 17, 2026 at 19:20 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT474694 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the cumulative security update 9.1.0.38 for IBM MQ 9.1 LTS
  • Apply the cumulative security update 9.2.0.44 for IBM MQ 9.2 LTS
  • Apply the cumulative security update 9.3.0.42 for IBM MQ 9 cumulative security update 9.4.0.26 for IBM MQ 9.4 LTS
  • Upgrade to IBM MQ 10.0.0.5 if running IBM MQ 10.0.0.0, 9.3 CD, or 9.4 CD
  • If an upgrade is not immediately feasible, reconfigure the XML parser to disallow external entity processing to mitigate the risk temporarily

Generated by OpenCVE AI on September 17, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Title IBM MQ Managed File Transfer is vulnerable to XML external entity injection
First Time appeared Ibm
Ibm mq
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:46.769Z

Reserved: 2026-06-24T21:53:50.072Z

Link: CVE-2026-13287

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:44.372Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:01.977

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-13287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference