Description
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM MQ’s XA transaction handling contains a stack buffer overflow (CWE-122) that is triggered when an authenticated attacker submits a specially crafted XA transaction identifier. The overflow corrupts control data, which can allow execution of arbitrary code with the privileges of the MQ process or, if exploitation fails, can cause a denial of service by crashing the queue manager.

Affected Systems

Vulnerable instances include IBM MQ 9.1 LTS versions up to 9.1.0.37, 9.2 LTS up to 9.2.0.43, 9.3 LTS up to 9.3.5.1 and 9.4 LTS up to 9.4.5.1, as well as the 9.3 CD, 9.4 CD and the 10.0.0.0 build. All affected versions are patchable by applying the cumulative security updates listed in the vendor’s advisory (9.1.0.38 for 9.1, 9.2.0.44 for 9.2, 9.3.0.42 for 9.3, 9.4.0.26 for 9.4, or upgrading to 10.0.0.5 for the CD and 10.0.0.0 builds).

Risk and Exploitability

The CVSS score of 8.8 classifies the vulnerability as high severity. The EPSS score of <1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, but the remote code execution potential combined with the requirement for authenticated access means that the threat is significant. An attacker who can authenticate to the queue manager from a remote network can potentially compromise the host or disrupt service until a patch or mitigation is applied.

Generated by OpenCVE AI on September 19, 2026 at 17:10 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT473424 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the appropriate cumulative security update for your IBM MQ version (e.g., 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, or upgrade to 10.0.0.5).
  • If XA transaction functionality is not required, disable XA processing to remove the vulnerable code path.
  • Restrict MQ authentication to trusted users only, enforce strong password policies, and consider using role‑based access control to limit credential reuse.

Generated by OpenCVE AI on September 19, 2026 at 17:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:mq:*:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:continuous_delivery:*:*:*

Mon, 21 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
Title IBM MQ queue manager is vulnerable to remote code execution
First Time appeared Ibm
Ibm mq
Weaknesses CWE-122
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-21T12:47:23.132Z

Reserved: 2026-06-05T12:32:17.660Z

Link: CVE-2026-11375

cve-icon Vulnrichment

Updated: 2026-09-21T12:44:58.424Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:05.470

Modified: 2026-09-23T18:24:17.427

Link: CVE-2026-11375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:15:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow