CVE-2026-10025: IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labscore.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.
Other sources
IBM QRadar has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM QRadar SIEMto a version that resolves this vulnerability.Fixed in 7.6.0.2 - Upgrade
Upgrade
IBM QRadar SIEMto a version that resolves this vulnerability.Patch 7.5.0 UP15 IF05 Hotfix 20260715231428 - Compensating control
Restrict network access to QRadar syslog ingestion on port 514 (UDP/TCP) so XML-formatted syslog events cannot be sent without authentication (the XXE occurs when XML-format property autodetection is enabled and XML-formatted syslog events are processed on port 514 without authentication).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10025?
The severity of CVE-2026-10025 is rated as high with a score of 8.2.
How do I fix CVE-2026-10025?
To fix CVE-2026-10025, upgrade to IBM QRadar version 7.6.0.2 or later.
What type of vulnerability is CVE-2026-10025?
CVE-2026-10025 is classified as an XML External Entity (XXE) injection vulnerability.
Which versions of IBM QRadar are affected by CVE-2026-10025?
CVE-2026-10025 affects IBM QRadar versions 7.6.0.0 through 7.6.0.1 and 7.5.0 through 7.5.0 UP 15 Interim Fix 005.
What impact does CVE-2026-10025 have on data confidentiality?
CVE-2026-10025 can lead to a loss of data confidentiality due to the potential exposure of sensitive information.