CVE-2026-13275

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery due to XML external entity injection in reply message processing.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 21:17

Updated : 2026-09-15 19:17


NVD link : CVE-2026-13275

Mitre link : CVE-2026-13275

CVE.ORG link : CVE-2026-13275


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference