IBM QRadar 7.5-7.6 XXE via q1labs_core.jar (before 7.6.2)
CVE-2026-10025 Published on August 5, 2026

IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-10025 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and a small impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
NONE
Availability Impact:
LOW

Weakness Type

What is a XXE Vulnerability?

The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

CVE-2026-10025 has been classified to as a XXE vulnerability or weakness.


Products Associated with CVE-2026-10025

Want to know whenever a new CVE is published for IBM Qradar? stack.watch will email you.

 

Affected Versions

IBM QRadar: