CVE Tools

CVE-2026-1276

IBM QRadar SIEM Cross-Site Scripting

Published: Mar 19, 2026Updated: Mar 24, 2026 Sources: CVE List NVD BDUCWE-79

Description

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

In plain language

AI Low urgency

CVE-2026-1276 is a web bug in IBM QRadar SIEM that lets a low-privileged, logged-in user inject malicious code into the interface, potentially stealing session credentials; a typical small business should worry mainly if attackers can get a user account and can reach the QRadar web login.

Executive summary

CVE-2026-1276 is a cross-site scripting issue (CWE-79) in IBM QRadar SIEM web UI where a low-privileged authenticated user can inject JavaScript that executes in another user’s browser session, enabling session/credential theft and UI manipulation.

If affected, business impact
Session credential theftUser account takeover riskSecurity console tamperingOperational disruption

What to do now

  1. Check which IBM QRadar SIEM version and update level you run (e.g., 7.5.0 and whether you are past Update Package 14).
  2. If you are on IBM QRadar SIEM 7.5.0 through Update Package 14, plan an upgrade to the fixed level: IBM QRadar SIEM 7.5.0 UP15.
  3. Confirm the QRadar web interface is not exposed beyond what you need (and restrict access to trusted users/VPN/admin networks).
  4. Review access logs for unusual authenticated users or suspicious changes/inputs in the QRadar web UI around the time of any alerts.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:LUI:RS:CC:LI:LA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:RUser Interaction
Required
Scope
S:CScope
Changed
Impact
C:LConfidentiality
Low
I:LIntegrity
Low
A:NAvailability
None

Weaknesses

Affected Products

IBM
commercial·USaka international business machines
IBM Corp.
commercial·USaka ibm, ibm corporation

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Execution
Initial Access
View detailed technique mapping

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-1276 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows