Description
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM MQ’s distribution list processing contains an integer overflow that an authenticated attacker can exploit to cause a denial of service or, in certain conditions, execute arbitrary code. The flaw is classified as CWE-190, an integer overflow vulnerability that can corrupt memory boundaries and lead to privilege escalation or crash. As the attack requires valid credentials, the impact is limited to environments where the attacker can log in as a user with sufficient permissions to send messages to the vulnerable queue manager.

Affected Systems

Affected versions include IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.4 LTS, the 9.3 CD, 9.4 CD, and 10.0.0.0 releases. IBM supplies cumulative security updates for each unless a newer major version is installed: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and an upgrade to 10.0.0.5 for the CD and 10.0.0.0 series.

Risk and Exploitability

The CVSS score of 8.8 reflects the severity of potential code execution. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog at this time. Exploitation can occur over the network from any host that can authenticate to the queue manager; it does not require physical access, and the flaw can be triggered by sending a crafted message or list to the distribution channel. Because the condition demands valid authentication, mitigations such as limiting user privileges or disabling unnecessary protocols can reduce risk, but the most effective defense is to apply the listed cumulative security updates.

Generated by OpenCVE AI on September 19, 2026 at 17:10 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT473420 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the IBM MQ 9.1 LTS cumulative security update 9.1.0.38 to all vulnerable 9.1 installations
  • Apply the IBM MQ 9.2 LTS cumulative security update 9.2.0.44 to all vulnerable 9.2 installations
  • Apply the IBM MQ 9.3 LTS cumulative security update 9.3.0.42 to all vulnerable 9.3 installations
  • Apply the IBM MQ 9.4 LTS cumulative security update 9.4.0.26 to all vulnerable 9.4 installations
  • Upgrade any remaining 9.3 CD, 9.4 CD, or 10.0.0.0 installations to IBM MQ 10.0.0.5
  • If immediate patching is not possible, restrict network access to the MQ server and monitor for abnormal traffic patterns

Generated by OpenCVE AI on September 19, 2026 at 17:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:mq:*:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:continuous_delivery:*:*:*

Mon, 21 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.
Title IBM MQ queue manager is vulnerable to remote code execution
First Time appeared Ibm
Ibm mq
Weaknesses CWE-190
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-21T12:47:22.963Z

Reserved: 2026-06-05T12:46:09.923Z

Link: CVE-2026-11378

cve-icon Vulnrichment

Updated: 2026-09-21T12:44:56.154Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:05.620

Modified: 2026-09-23T18:23:54.403

Link: CVE-2026-11378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:15:04Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound