{"id":"CVE-2026-10025","published":"2026-08-05T16:16:49.197","lastModified":"2026-08-10T19:36:16.843","description":"IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.","cvssScore":8.2,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","cwes":["CWE-611"],"vendors":["ibm"],"products":["qradar security information and event manager"],"references":[{"url":"https://www.ibm.com/support/pages/node/7282394","tags":["Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is an XML External Entity (XXE) injection vulnerability in IBM QRadar versions 7.6.0.0 to 7.6.0.1 and 7.5.0 to 7.5.0 UP 15 Interim Fix 005, allowing attackers to inject malicious XML content and potentially access sensitive information.","exploitability":"Exploitation requires a configured log source type using XML-format property autodetection and sending XML-formatted syslog events to port 514 (UDP/TCP). It is moderately hard due to specific configuration requirements.","blast_radius":"If exploited, the vulnerability could lead to unauthorized access to sensitive information within the QRadar system, impacting data confidentiality.","remediation":"Update IBM QRadar to a patched version or disable XML-format property autodetection for log sources.","tags":["xxe","xml-injection","info-leak","patch-required"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:49:42.553Z"}}