VYPR
Medium severity6.8NVD Advisory· Published Sep 14, 2026

CVE-2026-13265

CVE-2026-13265

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1
  • IBM/MQllm-fuzzy
    Range: 9.1.0.0-9.1.0.37 LTS, 9.2.0.0-9.2.0.43 LTS, 9.3.0.0-9.3.0.41 LTS, 9.3.0.0-9.3.5.1 CD, 9.4.0.0-9.4.0.25 LTS, 9.4.0.0-9.4.5.1 CD, 10.0.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.