CVE-2026-11726: IBM MQ for HPE NonStop is vulnerable to a denial of service issue
IBM MQ could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.
Other sources
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ V8.1 for HPE NonStopto a version that resolves this vulnerability.Fixed in 8.1.0.41Patch IT49920 - Compensating control
If you cannot immediately install CSU 8.1.0.41, temporarily restrict access to IBM MQ so only trusted clients can authenticate and send messages, reducing exposure to authenticated attacks exploiting improper validation of message header offset values.
Event History
Frequently Asked Questions
Which deployments are affected?
IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 are identified as affected.
What access does an attacker need?
Exploitation requires an authenticated attacker. The issue is network-accessible and does not require user interaction.
What impact can exploitation have?
An attacker may obtain sensitive information or cause a denial of service. The provided severity vector indicates high confidentiality and availability impact, with no integrity impact.