CVE-2026-10030: IBM MQ Console is vulnerable to privilege escalation
Published Sep 14, 2026
·Updated
IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks
Affected Software
6 affected components
IBM IBM MQ Console
IBM MQ<=9.3.0.0 to 9.3.0.41 LTS
IBM MQ<=9.3.0.0 to 9.3.5.1 CD
IBM MQ<=9.4.0.0 to 9.4.0.25 LTS
IBM MQ<=9.4.0.0 to 9.4.5.1 CD
IBM MQ<=10.0.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQto a version that resolves this vulnerability.Fixed in 10.0.0.5
Event History
Sep 14, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 18, 2026
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker needs an authenticated IBM MQ Console account with non-administrative privileges. No user interaction is required.
2
What can a successful attacker do?
A non-administrative user can create and start queue managers through the IBM MQ Console, actions that should require stronger authorization. The reported impact includes integrity impact and high availability impact.