CVE-2026-12666
Received Received - Intake

IBM MQ Java Classes XML External Entity Injection Vulnerability

Vulnerability report for CVE-2026-12666, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: IBM Corporation

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Classes for Java could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to XML external entity injection in MQRFH2 header processing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
ibm mq From 9.1.0.0 (inc) to 9.1.0.37 (inc)
ibm mq From 9.2.0.0 (inc) to 9.2.0.43 (inc)
ibm mq From 9.3.0.0 (inc) to 9.3.0.41 (inc)
ibm mq From 9.3.0.0 (inc) to 9.3.5.1 (inc)
ibm mq From 9.4.0.0 (inc) to 9.4.0.25 (inc)
ibm mq From 9.4.0.0 (inc) to 9.4.5.1 (inc)
ibm mq 10.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an XML external entity (XXE) injection flaw in IBM MQ's Java messaging component, specifically in the RFH2 header parser of the IBM MQ Classes for Java client. An authenticated attacker could exploit this to access sensitive information or cause a denial of service.

Detection Guidance

Detection involves checking IBM MQ versions against affected ranges and monitoring for unusual XML processing in MQRFH2 headers. Use IBM MQ commands like 'dspmqver' to check installed versions and inspect network traffic for XML external entity patterns in MQRFH2 headers.

Impact Analysis

An attacker could obtain sensitive data or disrupt services by exploiting this flaw. The impact includes potential data breaches and service interruptions, depending on the system's configuration and exposure.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations must address this to maintain regulatory compliance.

Mitigation Strategies

Apply the latest IBM MQ cumulative updates or upgrade to a fixed version. Ensure all IBM MQ Classes for Java components are updated. Restrict network access to MQ servers and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12666. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart