CVE-2026-12666

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Classes for Java could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to XML external entity injection in MQRFH2 header processing.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-15 18:17

Updated : 2026-09-15 18:17


NVD link : CVE-2026-12666

Mitre link : CVE-2026-12666

CVE.ORG link : CVE-2026-12666


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference