Sceawere
Vulnerability Detail
CVE-2026-5522UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM QRadar Hard-Coded Credentials Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.7
- Creation Date
- 3h ago
- Vendor
- IBM
- Product
- QRadar
- Attack Type
- CWE-798 Use of Hard-coded Credentials
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.7",
"pubDate": "2026-09-04T16:17:25.870Z",
"pubdate": "2026-09-04T16:17:25.870Z",
"executiveSummary": "IBM QRadar versions 7.5.0 through 7.5.0 UP15 Interim Fix 005 are susceptible to a security vulnerability involving the use of hard-coded credentials.\nThe vulnerability stems from the inclusion of static passwords or cryptographic keys within the product's codebase, utilized for internal data encryption, inbound authentication, or communication with external components.\nThis flaw allows an attacker with access to the static credentials to potentially bypass authentication mechanisms, decrypt sensitive internal data, or intercept and manipulate outbound communications.\nThe risk implication is significant, as the exposure of these credentials compromises the confidentiality, integrity, and availability of the affected QRadar deployments.\nAn attacker does not necessarily require advanced privileges to exploit this, provided they can retrieve the hard-coded values from the application, which may be achievable through local file access or reverse engineering of binary components.\nGiven the nature of QRadar as a security intelligence platform, successful exploitation could lead to full system compromise or the exfiltration of sensitive security event data.",
"technicalDetails": "The root cause of this vulnerability is the implementation of hard-coded authentication tokens and cryptographic keys directly within the IBM QRadar application binaries or configuration files.\nThese credentials are used by the application to facilitate internal operations, including the protection of data at rest, secure handshakes for outbound communications to integrated external components, and authentication for inbound service requests.\nBecause these credentials are static and embedded within the product, they are distributed universally across all installations within the specified version range. An attacker can obtain these credentials through reverse engineering of the QRadar application files or by extracting them from the file system if they have sufficient local access.\nThe attack flow for exploiting this vulnerability typically follows these stages: First, the attacker identifies the vulnerable components that utilize the hard-coded secret. This may involve static analysis of the QRadar binary files or monitoring inter-component traffic to observe the utilization of a consistent, hard-coded key or credential.\nOnce the secret is recovered, the attacker can leverage it to authenticate as an authorized component or user to the target interface. In scenarios where the credential is used for encryption, the attacker can use the discovered key to decrypt sensitive data streams or internal databases, potentially gaining access to PII, configuration secrets, or security log data.\nFurthermore, because the credential is used for outbound communication, an attacker might perform man-in-the-middle (MITM) attacks on internal network segments, presenting the stolen credential to impersonate legitimate QRadar services, thereby facilitating data injection or unauthorized command execution within the wider infrastructure that trusts the QRadar node.\nThe scope of impact is broad, as it affects any QRadar deployment from 7.5.0 up to and including 7.5.0 UP15 Interim Fix 005. Exploitation does not require high-level privileges initially, as the static nature of the credential bypasses the need for knowledge of individual user passwords or dynamic authentication tokens.\nThe vulnerability persists across various internal modules that rely on this shared, hard-coded secret, making the entire internal trust architecture of the affected QRadar version susceptible to compromise."
}