Description
IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The IBM MQ Console mistakenly allows any authenticated non‑administrative user to create and start queue managers because authorization checks are not enforced. This flaw enables a user without administrative privileges to elevate their role within the messaging system, potentially modifying queue configurations, redirecting traffic, and compromising the integrity and availability of the MQ environment.

Affected Systems

IBM MQ deployments that include releases 9.3 LTS, 9.4 LTS, the 9.3 and 9.4 community development builds, and the 10.0.0.0 version are impacted. The vulnerability is resolved by applying cumulative security updates 9.3.0.42 and 9.4.0.26 for the LTS releases and upgrading to IBM MQ 10.0.0.5 for the CD builds and 10.0.0.0.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate‑to‑high risk. The EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. Because an attacker must be an authenticated non‑administrative user with console access, the attack vector is limited to environments where such users are granted visibility of the console; once logged in, the system permits creation and startup of queue managers, effectively elevating the attacker’s privileges.

Generated by OpenCVE AI on September 19, 2026 at 18:22 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT472093 IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 IBM MQ version 9.4 LTS Apply cumulative security update 9.4.0.26 IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5


OpenCVE Recommended Actions

  • Apply cumulative security update 9.3.0.42 for IBM MQ 9.3 LTS
  • Apply cumulative security update 9.4.0.26 for IBM MQ 9.4 LTS
  • Upgrade to IBM MQ 10.0.0.5 for any 9.3 CD, 9.4 CD or 10.0.0.0 releases
  • Restrict console user permissions so that only administrative accounts can create or start queue managers
  • Monitor console activity for unauthorized queue manager creation or startup

Generated by OpenCVE AI on September 19, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.
Title IBM MQ Console is vulnerable to privilege escalation
First Time appeared Ibm
Ibm mq
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T16:30:47.384Z

Reserved: 2026-05-28T18:33:26.331Z

Link: CVE-2026-10030

cve-icon Vulnrichment

Updated: 2026-09-18T16:29:47.514Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:04.020

Modified: 2026-09-18T18:17:47.257

Link: CVE-2026-10030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:30:16Z

Weaknesses