CVE-2026-13275: IBM MQ Managed File Transfer is vulnerable to XML external entity injection
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery due to XML external entity injection in reply message processing.
Other sources
IBM MQ Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery due to XML external entity injection in reply message processing.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0.0.0 Managed File Transferto a version that resolves this vulnerability.Fixed in 10.0.0.5 - Compensating control
Ensure the IBM MQ Managed File Transfer component is updated to the specified cumulative security update level(s) to address XML external entity injection in reply message processing (Known Issue: DT474689).
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be authenticated. Exploitation occurs through XML external entity injection in reply message processing.
What impact could successful exploitation have?
An authenticated attacker could read arbitrary files or perform server-side request forgery. The provided severity vector indicates high confidentiality impact, low integrity impact, and no availability impact.
Which deployments should be prioritized for review?
Review IBM MQ Managed File Transfer deployments running the listed 9.1, 9.2, 9.3, 9.4, or 10.0.0.0 versions, particularly where authenticated users can cause reply messages containing attacker-controlled XML to be processed.