CVE-2026-1567: IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability
Published Feb 18, 2026
·Updated
An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.
Affected Software
3 affected componentsFixes available
IBM InfoSphere Information Server>=11.7.0.0<=11.7.1.6
IBM InfoSphere Information Server<=11.7.0.0 to 11.7.1.6
IBM InfoSphere Information Server>=11.7<=11.7.1.6
Remediation
Information
ProductVersion(s)APARRemediationIBM InfoSphere Information Server11.7.0.0 to 11.7.1.6 DT461311 https://www.ibm.com/mysupport/s/defect/aCIgJ0000009mNB/dt461311 --Apply IBM InfoSphere Information Server version 11.7.1.0 https://www.ibm.com/support/pages/node/878310
--Apply IBM InfoSphere Information Server version 11.7.1.5 https://www.ibm.com/support/pages/node/7156680 or 11.7.1.6 https://www.ibm.com/support/pages/node/7182872
--Apply IBM InfoSphere Information Server security patch https://www.ibm.com/support/fixcentral/quickorder
Event History
Feb 18, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Mar 3, 2026
CVE Published
via MITRE·08:40 PM
Data Sourced
via MITRE·08:40 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-1567?
The severity of CVE-2026-1567 is considered significant due to its potential to allow unauthorized access to sensitive data.
2
How do I fix CVE-2026-1567?
To fix CVE-2026-1567, apply the latest patches provided by IBM for InfoSphere Information Server versions 11.7.0.0 to 11.7.1.6.
3
What types of attacks can CVE-2026-1567 facilitate?
CVE-2026-1567 can facilitate XML external entity injection attacks, enabling attackers to extract sensitive information.
4
Which versions of IBM InfoSphere Information Server are affected by CVE-2026-1567?
CVE-2026-1567 affects IBM InfoSphere Information Server versions from 11.7.0.0 to 11.7.1.6.
5
Is CVE-2026-1567 a known vulnerability?
Yes, CVE-2026-1567 is a known vulnerability that has been documented and reported by cybersecurity experts.