VYPR
High severity7.1NVD Advisory· Published Sep 14, 2026

CVE-2026-13285

CVE-2026-13285

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1
  • IBM/MQllm-fuzzy
    Range: 9.1.0.0-9.1.0.37 LTS, 9.2.0.0-9.2.0.43 LTS, 9.3.0.0-9.3.0.41 LTS, 9.3.0.0-9.3.5.1 CD, 9.4.0.0-9.4.0.25 LTS, 9.4.0.0-9.4.5.1 CD, 10.0.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.