What is CVE-2026-13477?
CVE-2026-13477 is a vulnerability in IBM QRadar versions 7.6.0.0 through 7.6.0.1 and 7.5.0 through 7.5.0 UP 15 Interim Fix 005, which could allow an authenticated privileged user to execute arbitrary commands with normal user privileges due to improper input validation. Organizations using these affected versions should apply the official patches to mitigate the risk.
Azərbaycanca: CVE-2026-13477: IBM QRadar-ın göstərilən versiyalarında autentifikasiya olunmuş imtiyazlı istifadəçinin daxiletmənin düzgün yoxlanılmaması səbəbindən normal istifadəçi hüquqları ilə ixtiyari əmrlər icra etməsinə imkan verən boşluq aşkarlanıb. Bu, əməliyyat sistemində imtiyazları yüksəltmədən müəyyən əmrlərin icrasına şərait yarada bilər. Təsirə məruz qalan versiyaları istifadə edən təşkilatların rəsmi yamaqları tətbiq etməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20; shared vendor: IBM
FAQ2
Which versions of IBM QRadar are affected by CVE-2026-13477?
CVE-2026-13477 affects IBM QRadar versions 7.6.0.0 through 7.6.0.1 and versions 7.5.0 through 7.5.0 UP 15 Interim Fix 005.
How can CVE-2026-13477 be exploited?
An authenticated privileged user could exploit improper input validation to execute arbitrary commands with normal user privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.