Back

HIGH

IBM QRadar SIEM is vulnerable to remote code execution by privileged users

Published Aug 5, 2026

Description

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.

Affected products

Remediation

Vendor solution

IBM strongly encourages customers to update their systems promptly.

ProductVersionFixIBM QRadar SIEM 7.5.0  7.5.0 UP15 IF05 https://www.ibm.com/support/pages/release-qradar-750-update-package-15-interim-fix-05-sfs-202161520260715231428 IBM QRadar SIEM 7.6.0  7.6.0.2 https://www.ibm.com/support/pages/node/7280199

Metrics

References (1)

Change history (3)
  1. CISA ADP
    • SSVC technical impact changed from total to partial
  2. CISA ADP
    • SSVC technical impact changed from partial to total
  3. CISA ADP
    • SSVC technical impact changed from total to partial
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Aug 5, 2026
Updated Aug 6, 2026
Reserved Jun 27, 2026
CISA Vulnrichment
Updated Aug 5, 2026
NVD
Status Analyzed
Modified Aug 10, 2026
Red Hat
Severity n/a
Public date n/a