CVE-2026-1276: IBM QRadar SIEM Cross-Site Scripting
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1276?
CVE-2026-1276 is classified as a medium severity vulnerability due to its potential impact on user session integrity.
How do I fix CVE-2026-1276?
To fix CVE-2026-1276, update IBM QRadar SIEM to the latest version available beyond 7.5.0 Update Package 14.
Who is affected by CVE-2026-1276?
CVE-2026-1276 affects all authenticated users of IBM QRadar SIEM versions from 7.5.0 to 7.5.0 Update Package 14.
What type of vulnerability is CVE-2026-1276?
CVE-2026-1276 is a cross-site scripting (XSS) vulnerability.
What can an attacker achieve with CVE-2026-1276?
An attacker can inject arbitrary JavaScript into the IBM QRadar SIEM Web UI, potentially leading to credential theft or session hijacking.