SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-13265

MEDIUM · CVSS 6.8 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM MQ versions 9.1 through 10.0 are vulnerable to XML external entity injection in the mqweb MFT REST API, which could allow authenticated attackers with MFT publish authority to access sensitive information or trigger a denial of service. Organizations using these specific versions should prioritize patching to mitigate the risk of data exposure and service disruption. This vulnerability is particularly relevant for those managing sensitive data or critical messaging services.

CVE
CVE-2026-13265
Severity
MEDIUM
CVSS
6.8
EPSS
0.22%

Original NVD Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API.