---
id: CVE-2026-13265
title: >-
  IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0
  through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25
  LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated
  attacker wit…
summary: >-
  IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0
  through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25
  LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated
  attacker wit…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-611
vendor: IBM
product: MQ
affected:
  - MQ >= 9.1.0.0 <= 9.1.0.37 LTS
  - MQ >= 9.2.0.0 <= 9.2.0.43 LTS
  - MQ >= 9.3.0.0 <= 9.3.0.41 LTS
  - MQ >= 9.3.0.0 <= 9.3.5.1 CD
  - MQ >= 9.4.0.0 <= 9.4.0.25 LTS
  - MQ >= 9.4.0.0 <= 9.4.5.1 CD
  - MQ 10.0.0.0
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:24:58.293'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13265'
references:
  - url: 'https://www.ibm.com/support/pages/node/7284895'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
epss: 0.00223
epssPercentile: 0.11494
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T17:25:02.252072Z'
ingestedAt: '2026-09-14T22:16:09.898Z'
---

## Overview

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
