CVE-2026-11725: IBM MQ queue manager is vulnerable to privilege escalation
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0to a version that resolves this vulnerability.Fixed in 10.0.0.5Patch DT473418
Event History
Frequently Asked Questions
Can this be exploited remotely without user interaction?
The CVSS vector indicates network-based exploitation with low attack complexity and no user interaction required. The attacker must already be authenticated.
How much access does an attacker need before attempting exploitation?
The CVSS vector lists low privileges required, indicating that an authenticated account with limited privileges may be sufficient.