---
id: CVE-2026-13287
title: >-
  IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0
  through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25
  LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external
  entity i…
summary: >-
  IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0
  through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25
  LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external
  entity i…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'
cwe:
  - CWE-611
vendor: IBM
product: MQ
affected:
  - MQ >= 9.1.0.0 <= 9.1.0.37 LTS
  - MQ >= 9.2.0.0 <= 9.2.0.43 LTS
  - MQ >= 9.3.0.0 <= 9.3.0.41 LTS
  - MQ >= 9.3.0.0 <= 9.3.5.1 CD
  - MQ >= 9.4.0.0 <= 9.4.0.25 LTS
  - MQ >= 9.4.0.0 <= 9.4.5.1 CD
  - MQ 10.0.0.0
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:24:58.293'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13287'
references:
  - url: 'https://www.ibm.com/support/pages/node/7284937'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
epss: 0.00385
epssPercentile: 0.29714
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T17:20:29.868874Z'
ingestedAt: '2026-09-14T21:15:17.457Z'
---

## Overview

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
