Junglewise Threat Intelligence

CVE-2026-13275: IBM MQ Managed File Transfer XML external entity injection

CVE-2026-13275 · Severity: high · CVSS 7.1 · Published 2026-09-14

Technologies: IBM Mq. Vendors: IBM.

Executive brief

IBM MQ's Managed File Transfer component processes XML messages from authenticated users. An attacker with valid credentials could exploit an XML external entity (XXE) vulnerability to read arbitrary files from the server or perform server-side request forgery attacks, potentially exposing sensitive configuration data or facilitating further attacks on internal systems.

Technical details

This is an XML external entity (XXE) injection vulnerability (CWE-611) in the Managed File Transfer agent's reply message processing. The vulnerable component fails to properly restrict XML external entity references, allowing an authenticated attacker to craft malicious XML payloads. Attack vector is network-based with low complexity; authentication is required as a precondition. Successful exploitation enables arbitrary file read and server-side request forgery (SSRF). IBM has released cumulative security updates for affected versions: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and 10.0.0.5.

Affected products

  • IBM MQ 9.1.0.0 to 9.1.0.37 LTS, 9.2.0.0 to 9.2.0.43 LTS, 9.3.0.0 to 9.3.0.41 LTS, 9.3.0.0 to 9.3.5.1 CD, 9.4.0.0 to 9.4.0.25 LTS, 9.4.0.0 to 9.4.5.1 CD, 10.0.0.0

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Security updates available: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and 10.0.0.5

References

Related threats