CVE-2026-5522: QRadar contains hard-coded credentials
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Other sources
QRadar contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.5.0 UP15 IF06 - Operational
Update IBM QRadar SIEM 7.5.0 through 7.5.0 UP15 Interim Fix 005 promptly because it contains hard-coded credentials (password or cryptographic key) used for inbound authentication, outbound communication to external components, or encryption of internal data.
Event History
Frequently Asked Questions
Which QRadar versions are affected?
IBM QRadar versions 7.5.0 through 7.5.0 UP15 Interim Fix 005 are affected.
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs high privileges and local access. No user interaction is required.
What is the potential impact if exploited?
The issue can expose confidential information and allow limited modification of data. The CVSS vector indicates no availability impact.