CVE-2026-10025

EUVD-2026-53441
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 28.43%
Affected Products (NVD)
VendorProductVersion
ibmqradar_security_information_and_event_manager
7.5.0
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_1
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_10
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_11
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_12
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_13
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_13_interim_fix_01
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_13_interim_fix_02
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_14
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_14_interim_fix_01
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_14_interim_fix_02
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_15
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_15_interim_fix_01
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_15_interim_fix_02
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_15_interim_fix_03
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_15_interim_fix_04
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_2
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_3
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_4
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_5
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_6
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_7
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_8
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_9
ibmqradar_security_information_and_event_manager
7.6.0
ibmqradar_security_information_and_event_manager
7.6.0:fix_pack_1
𝑥
= Vulnerable software versions