CVE-2026-13477

EUVD-2026-53439
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.7 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 17.98%
Affected Products (NVD)
VendorProductVersion
ibmqradar_security_information_and_event_manager
7.5.0
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_1
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_10
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_11
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_12
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_13
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_13_interim_fix_01
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_13_interim_fix_02
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_14
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_14_interim_fix_01
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_14_interim_fix_02
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_15
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_15_interim_fix_01
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_15_interim_fix_02
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_15_interim_fix_03
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_15_interim_fix_04
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_2
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_3
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_4
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_5
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_6
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_7
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_8
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_9
ibmqradar_security_information_and_event_manager
7.6.0
ibmqradar_security_information_and_event_manager
7.6.0:fix_pack_1
𝑥
= Vulnerable software versions