CVE-2026-13477
Description
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
Summary dbcve.org
IBM QRadar versions 7.5.0 through 7.5.0 UP15 IF005 and 7.6.0.0 through 7.6.0.1 contain an input validation vulnerability that allows an authenticated privileged user to execute arbitrary system commands on the underlying operating system, albeit with normal (non-privileged) user rights rather than elevated administrator/root privileges.
Mitigation
Apply IBM's published interim fixes or patches for these specific QRadar versions to address the input validation flaw; in the interim, implement strict least-privilege access controls and network segmentation to limit exposure.