CVE-2026-10025
8.2 HIGHPublished 2026-08-05 · Updated 2026-08-10
AI risk analysis
- Summary
- The flaw is an XML External Entity (XXE) injection vulnerability in IBM QRadar versions 7.6.0.0 to 7.6.0.1 and 7.5.0 to 7.5.0 UP 15 Interim Fix 005, allowing attackers to inject malicious XML content and potentially access sensitive information.
- Exploitability
- Exploitation requires a configured log source type using XML-format property autodetection and sending XML-formatted syslog events to port 514 (UDP/TCP). It is moderately hard due to specific configuration requirements.
- Blast radius
- If exploited, the vulnerability could lead to unauthorized access to sensitive information within the QRadar system, impacting data confidentiality.
- Prioritized remediation
- Update IBM QRadar to a patched version or disable XML-format property autodetection for log sources.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Weaknesses
CWE-611
Vendors
ibm
Products
qradar security information and event manager
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.