Skip to content
Threat Feed
high advisory

IBM MQ XML External Entity Injection Vulnerability

An XML external entity injection vulnerability in IBM MQ allows authenticated attackers to perform arbitrary file reads or server-side request forgery during reply message processing.

CVE search metadata

CVE search record: CVE-2026-13275. Severity: high. CVSS: 7.1. KEV: no. Product: MQ (9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, 10.0.0.0 Managed File Transfer). Brief: IBM MQ XML External Entity Injection Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-xxe/

IBM MQ, a message-oriented middleware solution, contains a vulnerability identified as CVE-2026-13275 that stems from improper handling of XML input during reply message processing. This vulnerability enables an authenticated attacker to perform XML External Entity (XXE) injection attacks. By submitting specifically crafted XML messages, an attacker can coerce the IBM MQ application into reading arbitrary files from the host filesystem or performing unauthorized Server-Side Request Forgery (SSRF) requests to internal or external network resources. This flaw impacts multiple long-term support (LTS) and continuous delivery (CD) versions of IBM MQ, as well as the Managed File Transfer component. Given that IBM MQ often handles sensitive financial or operational data, successful exploitation could lead to the exposure of configuration files, credentials, or internal network mapping.

Impact

The vulnerability allows authenticated attackers to bypass security boundaries within the messaging environment. Successful exploitation leads to unauthorized access to sensitive local files and the ability to conduct SSRF, potentially escalating access within the internal network. The scope covers a wide range of IBM MQ versions, impacting organizations relying on this middleware for enterprise application integration. If exploited, an attacker could exfiltrate configuration data or pivot to other internal services that are not directly exposed to the internet.

Recommendation

Prioritized actions for security and IT teams:

  • Patch IBM MQ installations to the latest version as recommended by IBM to remediate CVE-2026-13275.
  • Audit IBM MQ message flow configurations to identify and restrict untrusted XML input sources.
  • Monitor MQ audit logs for unusual file access patterns or connection attempts originating from the IBM MQ service account.

Immediate actions

Patch all vulnerable IBM MQ versions identified in CVE-2026-13275.

IT Operations 72h

Mitigations

Upgrade to the latest non-vulnerable version of IBM MQ.

immediate IT Operations

CVE-2026-13275