Vulnerability Description
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-10025?
CVE-2026-10025 is a vulnerability with a CVSS score of 8.2 (HIGH). IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function ...
How severe is CVE-2026-10025?
CVE-2026-10025 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-10025?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.