PT-2026-92156 · Ibm · Ibm Mq

CVE-2026-12667

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions IBM MQ versions 9.1.0.0 through 9.1.0.37 LTS IBM MQ versions 9.2.0.0 through 9.2.0.43 LTS IBM MQ versions 9.3.0.0 through 9.3.0.41 LTS IBM MQ versions 9.3.0.0 through 9.3.5.1 CD IBM MQ versions 9.4.0.0 through 9.4.0.25 LTS IBM MQ versions 9.4.0.0 through 9.4.5.1 CD IBM MQ version 10.0.0.0
Description An authenticated attacker can read files from a .NET client or cause a limited denial of service. This is caused by the improper handling of XML External Entities (XXE) during the parsing of RFH2 folders. XXE is a type of attack where an application processes external entity references within an XML document, potentially allowing access to unauthorized files or system resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12667

Affected Products

Ibm Mq