Description
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The flaw in IBM MQ for HPE NonStop stems from improper validation of message distribution list structures, permitting an authenticated attacker to send crafted messages that can crash the system or, in some cases, execute arbitrary code. This corresponds to a heap-based buffer exploitation weakness.

Affected Systems

IBM MQ for HPE NonStop 8.1.0.40 and any earlier 8.1.0 releases are affected. The product is deployed on the HPE NonStop platform. IBM advises installing CSU 8.1.0.41 to remediate the issue.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8, indicating high severity, with an EPSS score of 0.0059 and not listed in the CISA KEV catalog. An attacker must have authenticated access and the ability to target distribution lists, suggesting a need for privileged accounts, but the potential for denial of service or remote code execution warrants rapid mitigation.

Generated by OpenCVE AI on September 19, 2026 at 17:30 UTC.

Remediation

Vendor Solution

IBM MQ V8.1 for HPE NonStop 8.1.0.40IT49925Upgrade to CSU 8.1.0.41 IBM strongly recommends addressing this vulnerability now by installing CSU 8.1.0.41.


OpenCVE Recommended Actions

  • Upgrade IBM MQ for HPE NonStop to CSU 8.1.0.41.
  • Limit privileged user rights so only trusted personnel can create or modify message distribution lists.
  • Monitor MQ logs for abnormal distribution list modifications and alert on suspicious activity.

Generated by OpenCVE AI on September 19, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.
Title IBM MQ for HPE NonStop is vulnerable to a denial of service issue
First Time appeared Ibm
Ibm mq For Hpe Nonstop
Weaknesses CWE-122
CPEs cpe:2.3:a:ibm:mq_for_hpe_nonstop:8.1.0.40:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_for_hpe_nonstop:8.1.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq For Hpe Nonstop
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Mq For Hpe Nonstop
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T03:56:53.756Z

Reserved: 2026-06-05T12:53:41.576Z

Link: CVE-2026-11381

cve-icon Vulnrichment

Updated: 2026-09-18T17:23:16.094Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:05.767

Modified: 2026-09-19T04:17:53.313

Link: CVE-2026-11381

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:45:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow