Junglewise Threat Intelligence

CVE-2026-13265: IBM MQ XML external entity injection in Managed File Transfer

CVE-2026-13265 · Severity: medium · CVSS 6.8 · Published 2026-09-14

Technologies: IBM Mq. Vendors: IBM.

Executive brief

IBM MQ is messaging middleware used for reliable communication between applications across distributed systems. An authenticated attacker with Managed File Transfer publish authority can exploit an XML external entity (XXE) vulnerability in the REST API to read sensitive files or cause the service to become unavailable, impacting business-critical messaging operations.

Technical details

The vulnerability is an XML external entity (XXE) injection (CWE-611) in the Managed File Transfer component of the IBM MQ REST API (mqweb). An authenticated attacker with MFT publish authority can craft malicious XML payloads to reference external entities, allowing disclosure of sensitive information or triggering denial of service. The vulnerability requires valid MFT publish credentials and network access to the REST API endpoint. Patches are available for all supported versions: 9.1.0.38, 9.2.0.44, 9.3.0.42 (LTS branches) and 10.0.0.5 (CD/latest branches).

Affected products

  • IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, 10.0.0.0

Timeline

  • 2026-09-14: disclosed: IBM security bulletin published
  • 2026-09-14: patched: Fixes released: 9.1.0.38, 9.2.0.44, 9.3.0.42 LTS and 10.0.0.5 CD

References

Related threats