Junglewise Threat Intelligence

CVE-2024-56462: IBM QRadar OS access via malicious backup archive

CVE-2024-56462 · Severity: high · CVSS 7.2 · Published 2026-05-27

Vendors: IBM.

Executive brief

IBM QRadar, a security information and event management (SIEM) platform used to monitor corporate networks for threats, is vulnerable to a security bypass. An authorized user with high-level administrative privileges can upload a specially crafted backup file that, when restored, allows them to gain full control over the underlying operating system. This could lead to a complete compromise of the security appliance and the sensitive data it manages.

Technical details

A vulnerability in the backup and restore functionality of IBM QRadar (CVE-2024-56462) allows for an escape from the application layer to the underlying operating system. The flaw is categorized as CWE-530 (Exposure of Backup File to an Unauthorized Control Sphere). An attacker with high privileges (PR:H) can upload a malicious backup archive via the network. Upon restoration of this archive, the system fails to properly validate or contain the contents, allowing the attacker to execute commands or place files that grant shell access to the OS. IBM has addressed this in QRadar SIEM 7.5.0 UP15 IF03.

Affected products

  • IBM QRadar SIEM 7.5.0 through 7.5.0 UP15 Interim Fix 002

Timeline

  • 2026-05-27: disclosed: Initial NVD publication date
  • 2026-05-27: advisory: IBM security bulletin published

References