---
id: CVE-2026-13275
title: >-
  IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0
  through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25
  LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could
  allow an auth…
summary: >-
  IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0
  through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25
  LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could
  allow an auth…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-611
vendor: IBM
product: MQ
affected:
  - MQ >= 9.1.0.0 <= 9.1.0.37 LTS
  - MQ >= 9.2.0.0 <= 9.2.0.43 LTS
  - MQ >= 9.3.0.0 <= 9.3.0.41 LTS
  - MQ >= 9.3.0.0 <= 9.3.5.1 CD
  - MQ >= 9.4.0.0 <= 9.4.0.25 LTS
  - MQ >= 9.4.0.0 <= 9.4.5.1 CD
  - MQ 10.0.0.0
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:24:58.293'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13275'
references:
  - url: 'https://www.ibm.com/support/pages/node/7284897'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
epss: 0.00251
epssPercentile: 0.14837
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T17:38:33.406653Z'
ingestedAt: '2026-09-14T21:15:17.455Z'
---

## Overview

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery due to XML external entity injection in reply message processing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
