← Browse

CVE-2026-13477

Low

No strong exploitation signal.

CVSS base
4.7 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
EPSS — probability of exploitation (30 days)
0.3%
18.0th percentile
CISA KEV
Not listed
Weakness / dates
CWE-78
Published 2026-08-05 · modified 2026-08-10

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredHHigh
User InteractionNNone
ScopeUUnchanged
ConfidentialityLLow
IntegrityLLow
AvailabilityLLow

Timeline

Description

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.

Affected

ibm

References

Official: NVD · CVE.org