CVE-2026-12667
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to read files from a vulnerable .NET client or cause limited denial of service due to improper handling of XML external entities in RFH2 folder parsing.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
- EPSS probability
- 0.36%
- CWE
- CWE-611
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- IBM MQ
- IBM MQ
- IBM MQ
- IBM MQ
- IBM MQ
Weakness type
Related vulnerabilities
- CVE-2025-58360 — GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
- CVE-2025-2776 — SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
- CVE-2025-2775 — SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
- CVE-2025-68493 — Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component
- CVE-2025-11700 — N-central Multiple XXE Injection Vulnerabilities
- CVE-2025-2777 — SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
- CVE-2025-30220 — GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling
- CVE-2026-32251 — Tolgee has an XXE Injection in Translation Import