Description
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and potential privilege escalation
Action: Patch Immediately
AI Analysis

Impact

IBM MQ for HPE NonStop is affected by an integer overflow in the MQINQ request validation. The flaw allows an authenticated attacker to send crafted requests that overload internal counters, causing the message queue to crash and result in a denial of service. In addition, the overflow could potentially lead to unauthorized escalation of privileges on the affected system by corrupting internal state.

Affected Systems

The vulnerability impacts IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40. The supported fix is the IBM MQ V8.1 for HPE NonStop 8.1.0.40IT49923 upgrade to CSU 8.1.0.41.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack requires authentication against the MQ server; therefore, the likely attack vector is an internal or remote authenticated user with privileges to issue MQINQ requests.

Generated by OpenCVE AI on September 19, 2026 at 17:18 UTC.

Remediation

Vendor Solution

IBM MQ V8.1 for HPE NonStop 8.1.0.40IT49923 Upgrade to CSU 8.1.0.41 https://www.ibm.com/support/fixcentral/swg/selectFixes IBM strongly recommends addressing this vulnerability now by installing CSU 8.1.0.41.


OpenCVE Recommended Actions

  • Upgrade the IBM MQ for HPE NonStop installation to CSU 8.1.0.41 to eliminate the integer overflow flaw.
  • Apply strict access controls on the MQ service so that only trusted users can submit MQINQ commands, reducing the attack surface for authenticated attackers.
  • After the upgrade and access‑control changes, monitor MQ logs and system performance for signs of abnormal MQINQ activity or service interruptions to confirm the effectiveness of the remediation.

Generated by OpenCVE AI on September 19, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
Title IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation
First Time appeared Ibm
Ibm mq For Hpe Nonstop
Weaknesses CWE-122
CPEs cpe:2.3:a:ibm:mq_for_hpe_nonstop:8.1.0.40:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_for_hpe_nonstop:8.1.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq For Hpe Nonstop
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Mq For Hpe Nonstop
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T03:56:44.901Z

Reserved: 2026-06-03T13:30:42.102Z

Link: CVE-2026-10744

cve-icon Vulnrichment

Updated: 2026-09-18T17:32:02.754Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:04.290

Modified: 2026-09-19T04:17:50.697

Link: CVE-2026-10744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:30:07Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow