CVE-2026-1276
IBM QRadar SIEM Cross-Site Scripting
Description
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
In plain language
AI Low urgencyCVE-2026-1276 is a web bug in IBM QRadar SIEM that lets a low-privileged, logged-in user inject malicious code into the interface, potentially stealing session credentials; a typical small business should worry mainly if attackers can get a user account and can reach the QRadar web login.
CVE-2026-1276 is a cross-site scripting issue (CWE-79) in IBM QRadar SIEM web UI where a low-privileged authenticated user can inject JavaScript that executes in another user’s browser session, enabling session/credential theft and UI manipulation.
What to do now
- Check which IBM QRadar SIEM version and update level you run (e.g., 7.5.0 and whether you are past Update Package 14).
- If you are on IBM QRadar SIEM 7.5.0 through Update Package 14, plan an upgrade to the fixed level: IBM QRadar SIEM 7.5.0 UP15.
- Confirm the QRadar web interface is not exposed beyond what you need (and restrict access to trusted users/VPN/admin networks).
- Review access logs for unusual authenticated users or suspicious changes/inputs in the QRadar web UI around the time of any alerts.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:CScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-1276 and every CVE in our database. Create a free account — no credit card required.
Create Free Account