HIGH

CVE-2026-13477

Ibm Qradar Security Information And Event Manager 2026-08-05 CVSS v3.1
CVSS
8.8

Description

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.

Summary dbcve.org

IBM QRadar versions 7.5.0 through 7.5.0 UP15 IF005 and 7.6.0.0 through 7.6.0.1 contain an input validation vulnerability that allows an authenticated privileged user to execute arbitrary system commands on the underlying operating system, albeit with normal (non-privileged) user rights rather than elevated administrator/root privileges.

Mitigation

Apply IBM's published interim fixes or patches for these specific QRadar versions to address the input validation flaw; in the interim, implement strict least-privilege access controls and network segmentation to limit exposure.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

0.26%
Probability of exploitation in next 30 days
18th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE