Junglewise Threat Intelligence

CVE-2026-5522: IBM QRadar hard-coded credentials in authentication and encryption

CVE-2026-5522 · Severity: medium · CVSS 6.7 · Published 2026-09-04

Vendors: IBM.

Executive brief

IBM QRadar, a security information and event management (SIEM) system used to monitor and analyze security events across enterprise networks, contains hard-coded credentials embedded in the software. These credentials are used for the system's internal authentication, communication with external components, and encryption of sensitive data. An attacker with access to QRadar could potentially extract these credentials to authenticate to the system or decrypt protected data, compromising the security of the entire monitoring infrastructure.

Technical details

The vulnerability is a hard-coded credentials issue (CWE-798) in IBM QRadar versions 7.5.0 through 7.5.0 UP15 IF005, where cryptographic keys and passwords are embedded in the application code or configuration. These credentials are used for inbound authentication mechanisms, outbound communication to external components, and encryption of internal data. The attack requires local access (AV:L) and high-level privileges (PR:H), but provides high confidentiality impact (C:H) by enabling extraction of embedded credentials. IBM released a fix in QRadar 7.5.0 UP15 IF06. No known active exploitation in the wild has been reported.

Affected products

  • IBM QRadar 7.5.0 through 7.5.0 UP15 IF005

Timeline

  • 2026-09-04: disclosed
  • 2026-08-26: patched: Fix available in QRadar 7.5.0 UP15 IF06

References