Executive brief
IBM MQ is messaging middleware used for reliable communication between applications across distributed systems. An authenticated attacker with Managed File Transfer publish authority can exploit an XML external entity (XXE) vulnerability in the REST API to read sensitive files or cause the service to become unavailable, impacting business-critical messaging operations.
Technical details
The vulnerability is an XML external entity (XXE) injection (CWE-611) in the Managed File Transfer component of the IBM MQ REST API (mqweb). An authenticated attacker with MFT publish authority can craft malicious XML payloads to reference external entities, allowing disclosure of sensitive information or triggering denial of service. The vulnerability requires valid MFT publish credentials and network access to the REST API endpoint. Patches are available for all supported versions: 9.1.0.38, 9.2.0.44, 9.3.0.42 (LTS branches) and 10.0.0.5 (CD/latest branches).
Affected products
- IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, 10.0.0.0
Timeline
- 2026-09-14: disclosed: IBM security bulletin published
- 2026-09-14: patched: Fixes released: 9.1.0.38, 9.2.0.44, 9.3.0.42 LTS and 10.0.0.5 CD