← Back to searchJSON

CVE-2026-10025

8.2 HIGH

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The flaw is an XML External Entity (XXE) injection vulnerability in IBM QRadar versions 7.6.0.0 to 7.6.0.1 and 7.5.0 to 7.5.0 UP 15 Interim Fix 005, allowing attackers to inject malicious XML content and potentially access sensitive information.
Exploitability
Exploitation requires a configured log source type using XML-format property autodetection and sending XML-formatted syslog events to port 514 (UDP/TCP). It is moderately hard due to specific configuration requirements.
Blast radius
If exploited, the vulnerability could lead to unauthorized access to sensitive information within the QRadar system, impacting data confidentiality.
Prioritized remediation
Update IBM QRadar to a patched version or disable XML-format property autodetection for log sources.
xxexml-injectioninfo-leakpatch-required

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

Weaknesses

CWE-611

Vendors

ibm

Products

qradar security information and event manager

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.