CVE-2026-10744: IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation
Other sources
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ V8.1 for HPE NonStopto a version that resolves this vulnerability.Fixed in 8.1.0.41Patch IT49923
Event History
Frequently Asked Questions
Which deployments are affected?
IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 are affected.
What access does an attacker need?
An attacker must be authenticated and able to submit MQINQ requests. The issue is remotely reachable, but no user interaction is required.
What could exploitation cause?
Successful exploitation could cause a denial of service or potentially allow privilege escalation. The reported impact includes high confidentiality, integrity, and availability effects.