Full Report
IBM security advisory (AV26-922)
Analysis Summary
# Vulnerability: Multiple Flaws in IBM Products (MQ, Sterling File Gateway, Langflow)
## CVE Details
- **CVE ID:** CVE-2026-13293, CVE-2026-19290, and Unassigned (Langflow)
- **CVSS Score:** Up to 9.8 (Critical - Estimated based on RCE descriptions)
- **CWE:** CWE-94 (Improper Control of Generation of Code), CWE-284 (Improper Access Control)
## Affected Systems
- **Products & Versions:**
- **IBM MQ:** 10.0.0.0; ≤ 9.1.0.37 LTS; ≤ 9.2.0.43 LTS; ≤ 9.3.0.41 LTS; ≤ 9.3.5.1 CD; ≤ 9.4.0.25 LTS; ≤ 9.4.5.1 CD.
- **IBM Sterling File Gateway:** ≤ 6.2.0.6_1; 6.2.1.0 through 6.2.1.2; 6.2.2.0 through 6.2.2.1.
- **Langflow OSS:** ≤ 1.10.0; ≤ 1.10.2; ≤ 1.11.2; ≤ 1.11.5.
- **Configurations:** Systems utilizing Java messaging (MQ) or network-based security scanners (Langflow).
## Vulnerability Description
This advisory covers three distinct security issues:
1. **IBM MQ RCE:** A flaw in Java messaging allows for remote code execution (RCE) when processing untrusted input.
2. **Langflow Code Execution:** An incomplete blocklist in the security scanner allows an attacker to bypass restrictions and execute arbitrary code via the network.
3. **Sterling File Gateway Access Control:** Improper access control mechanisms allow unauthorized users to potentially gain elevated privileges or access sensitive data.
## Exploitation
- **Status:** Not explicitly reported as exploited in the wild; however, RCE vulnerabilities in messaging middleware are high-value targets.
- **Complexity:** Low to Medium (depending on specific product configuration).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Potential for full data exposure).
- **Integrity:** High (Potential for unauthorized system modification).
- **Availability:** High (Potential for service disruption via code execution).
## Remediation
### Patches
IBM recommends upgrading to the following versions or higher:
- **IBM MQ:** Apply the latest Fix Pack for your specific release stream (e.g., 9.4.0.x LTS or 9.4.x CD).
- **IBM Sterling File Gateway:** Update to versions beyond 6.2.2.1 or apply specific hotfixes provided in the vendor portal.
- **Langflow OSS:** Update to versions exceeding 1.11.5.
### Workarounds
- **MQ:** Disable Java messaging features if not required, or implement strict network segmentation to limit access to MQ ports.
- **Langflow:** Implement external Web Application Firewalls (WAF) to filter malicious payloads that bypass internal blocklists.
## Detection
- **Indicators of Compromise:** Monitor for unusual outbound network connections from MQ service accounts or unexpected file creations in Langflow directories.
- **Detection methods:** Utilize vulnerability scanners to identify outdated versions of the IBM MQ jars and Sterling File Gateway binaries. Review audit logs for "Improper Access" events in Sterling File Gateway.
## References
- **Vendor Advisories:**
- hxxps[://]www[.]ibm[.]com/support/pages/node/7284896 (MQ RCE)
- hxxps[://]www[.]ibm[.]com/support/pages/node/7287180 (Sterling File Gateway)
- hxxps[://]www[.]ibm[.]com/support/pages/node/7278919 (Langflow)
- **General Bulletin:** hxxps[://]www[.]ibm[.]com/support/pages/bulletin/