CVE-2026-11378: IBM MQ queue manager is vulnerable to remote code execution
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0to a version that resolves this vulnerability.Fixed in 10.0.0.5 - Compensating control
If you cannot upgrade immediately, mitigate exposure for the IBM MQ queue manager vulnerable to remote code execution by limiting network access to the queue manager to trusted hosts only.
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be authenticated and have low privileges. The available information does not identify a specific IBM MQ role or permission required beyond that.
Can this be exploited remotely without user interaction?
Yes. The CVSS vector indicates network-based exploitation with low attack complexity and no user interaction required.