CVE-2026-10575: IBM MQ queue manager is vulnerable to remote code execution
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0to a version that resolves this vulnerability.Fixed in 10.0.0.5 - Compensating control
Apply the fix referenced as Known Issue DT472393 to address the heap buffer overflow/RCE risk in IBM MQ when processing MQPUT operations with malformed distribution headers.
Event History
Frequently Asked Questions
What level of access does an attacker need?
An attacker must be authenticated to IBM MQ. The issue is remotely reachable and does not require user interaction.
What activity is involved in triggering the flaw?
The flaw is triggered while processing MQPUT operations that contain malformed distribution headers. Successful exploitation may cause a denial of service or potentially escalate privileges.