Description
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
Published: 2026-08-05
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM QRadar SIEM versions 7.5.0 through 7.6.0.1 are vulnerable to a command injection flaw that permits an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input. The vulnerability results in remote code execution on the underlying host, compromising system integrity.

Affected Systems

Affected products are IBM QRadar SIEM 7.5.0, the 7.5.0 UP15 Interim Fix 005 release, and IBM QRadar SIEM 7.6.0.0 and 7.6.0.1.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate severity, and the EPSS score is not available, suggesting limited data on exploit prevalence. The flaw is not listed in CISA’s KEV catalog, but it requires authenticated privileged access to exploit. An attacker with such credentials could execute any command, so the risk is significant for organizations that delegate privileged roles. The attack vector is inferred to be local operation by a privileged user; indirect remote exploitation is not described.

Generated by OpenCVE AI on August 5, 2026 at 18:06 UTC.

Remediation

Vendor Solution

IBM strongly encourages customers to update their systems promptly. ProductVersionFixIBM QRadar SIEM 7.5.0  7.5.0 UP15 IF05 https://www.ibm.com/support/pages/release-qradar-750-update-package-15-interim-fix-05-sfs-202161520260715231428 IBM QRadar SIEM 7.6.0  7.6.0.2 https://www.ibm.com/support/pages/node/7280199


OpenCVE Recommended Actions

  • Upgrade IBM QRadar SIEM to version 7.5.0 UP15 Interim Fix 005 or later, or to 7.6.0.2 or higher, following the links provided in the IBM advisory.
  • Restrict privileged user accounts to the minimum necessary permissions until the patch is verified on the environments.
  • Enable and monitor audit logging for command execution and privilege escalation events to detect potential misuse during the transition period.

Generated by OpenCVE AI on August 5, 2026 at 18:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
Title IBM QRadar SIEM is vulnerable to remote code execution by privileged users
First Time appeared Ibm
Ibm qradar
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:qradar:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar:7.5.0up15:interim_fix_005:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar:7.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar:7.6.0.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm qradar
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Ibm Qradar Qradar Security Information And Event Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-06T03:55:31.942Z

Reserved: 2026-06-27T02:34:12.895Z

Link: CVE-2026-13477

cve-icon Vulnrichment

Updated: 2026-08-05T16:12:38.893Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T16:16:49.863

Modified: 2026-08-10T17:31:31.740

Link: CVE-2026-13477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T21:30:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')