IBM QRadar 7.5-7.6 XXE via q1labs_core.jar (before 7.6.2)
CVE-2026-10025 Published on August 5, 2026
IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.
Vulnerability Analysis
CVE-2026-10025 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and a small impact on availability.
Weakness Type
What is a XXE Vulnerability?
The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVE-2026-10025 has been classified to as a XXE vulnerability or weakness.
Products Associated with CVE-2026-10025
Want to know whenever a new CVE is published for IBM Qradar? stack.watch will email you.
Affected Versions
IBM QRadar:- Version 7.6.0.0, <= 7.6.0.1 is affected.
- Version 7.5.0, <= 7.5.0 UP 15 Interim Fix 005 is affected.