CVE-2026-11716: IBM MQ for HPE NonStop is vulnerable to a denial of service attack
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.
Other sources
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ for HPE NonStop 8.1to a version that resolves this vulnerability.Fixed in 8.1.0.41Patch IT49922
Event History
Frequently Asked Questions
Which deployments are affected?
IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 are affected.
What does an attacker need to exploit this issue?
An attacker needs network access and authenticated, low-privileged access. Exploitation has high attack complexity and does not require user interaction.
When does the vulnerable processing occur, and what could result?
The issue occurs during queue manager startup when cluster migration data is improperly validated. A successful attack could cause a denial of service or potentially allow arbitrary code execution.