CVE-2025-36376: IBM Security Qradar Edr
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.
Affected products
- IBM Security Qradar Edr: from 3.12.0, before 3.12.24 (fixed in 3.12.24)
Published 2026-02-17. Last modified 2026-06-17.