{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-12666","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2026-06-18T19:13:47.535Z","datePublished":"2026-09-15T17:08:05.180Z","dateUpdated":"2026-09-17T16:22:00.550Z"},"containers":{"cna":{"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-09-15T17:08:05.180Z"},"title":"IBM MQ Java messaging is vulnerable to XML external entity injection","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-611","description":"CWE-611 Improper Restriction of XML External Entity Reference","type":"CWE"}]}],"affected":[{"vendor":"IBM","product":"MQ","versions":[{"status":"affected","version":"9.1.0.0","lessThanOrEqual":"9.1.0.37 LTS","versionType":"semver"},{"status":"affected","version":"9.2.0.0","lessThanOrEqual":"9.2.0.43 LTS","versionType":"semver"},{"status":"affected","version":"9.3.0.0","lessThanOrEqual":"9.3.0.41 LTS","versionType":"semver"},{"status":"affected","version":"9.3.0.0","lessThanOrEqual":"9.3.5.1 CD","versionType":"semver"},{"status":"affected","version":"9.4.0.0","lessThanOrEqual":"9.4.0.25 LTS","versionType":"semver"},{"status":"affected","version":"9.4.0.0","lessThanOrEqual":"9.4.5.1 CD","versionType":"semver"},{"status":"affected","version":"10.0.0.0"}],"cpes":["cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Classes for Java could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to XML external entity injection in MQRFH2 header processing.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Classes for Java could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to XML external entity injection in MQRFH2 header processing.</p>"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7284939","tags":["vendor-advisory","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseSeverity":"HIGH","baseScore":8.1,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}}],"solutions":[{"lang":"en","value":"This issue was addressed under Known Issue DT474364\n\n\n\nIBM MQ version 9.1 LTS\n\n\n\n Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts \n\n\n\nIBM MQ version 9.2 LTS\n\n\n\n Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts \n\n\n\nIBM MQ version 9.3 LTS\n\n\n\n Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts \n\n\n\nIBM MQ version 9.4 LTS\n\n\n\n Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts   9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts \n\n\n\nIBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0\n\n\n\n Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>This issue was addressed under Known Issue DT474364</p><p>IBM MQ version 9.1 LTS</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts\" rel=\"noopener noreferrer nofollow\">Apply cumulative security update 9.1.0.38</a></p><p>IBM MQ version 9.2 LTS</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts\" rel=\"noopener noreferrer nofollow\">Apply cumulative security update 9.2.0.44</a></p><p>IBM MQ version 9.3 LTS</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts\" rel=\"noopener noreferrer nofollow\">Apply cumulative security update 9.3.0.42</a></p><p>IBM MQ version 9.4 LTS</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts\" rel=\"noopener noreferrer nofollow\">Apply cumulative security update</a><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts\" rel=\"noopener noreferrer nofollow\"> 9.4.0.26</a></p><p>IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-100\" rel=\"noopener noreferrer nofollow\">Upgrade to IBM MQ version 10.0.0.5</a></p>"}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-17T16:21:49.943491Z","id":"CVE-2026-12666","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-17T16:22:00.550Z"}}]}}