CVE-2026-13285: IBM MQ Managed File Transfer is vulnerable to XML external entity injection
IBM MQ is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0.0.0 (impacted CD and 10.0.0.0)to a version that resolves this vulnerability.Fixed in 10.0.0.5 - Compensating control
Mitigate XXE risk by restricting access so only trusted sources can send XML data to IBM MQ (e.g., limit inbound connectivity to required clients/ports).
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable with low attack complexity, but the attacker needs low-level privileges. No user interaction is required.
What is the practical impact of successful exploitation?
An attacker may expose sensitive information or consume memory resources while IBM MQ Managed File Transfer processes XML data. The stated impacts are high confidentiality impact and low availability impact, with no integrity impact.
Which IBM MQ releases are affected?
Affected releases include MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0.