CVE-2026-13265: IBM MQ Managed File Transfer REST API is vulnerable to XML external entity injection
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API.
Other sources
IBM MQ could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0to a version that resolves this vulnerability.Fixed in 10.0.0.5 - Compensating control
Known issue reference for this vulnerability: DT474594.
Event History
Frequently Asked Questions
Who is able to exploit this issue?
An attacker must be authenticated and have MFT publish authority. The vulnerable component is the mqweb Managed File Transfer REST API.
What impact could successful exploitation have?
An attacker could obtain sensitive information or cause a denial of service through XML external entity injection.
Which IBM MQ releases are affected?
Affected releases include 9.1.0.0 through 9.1.0.37 LTS; 9.2.0.0 through 9.2.0.43 LTS; 9.3.0.0 through 9.3.0.41 LTS and 9.3.0.0 through 9.3.5.1 CD; 9.4.0.0 through 9.4.0.25 LTS and 9.4.0.0 through 9.4.5.1 CD; and 10.0.0.0.