CVE-2026-1713: IBM MQ is affected by an authority vulnerablility
IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.17 LTS, and 9.4.0.0 through 9.4.4.1 CD
Other sources
IBM MQ is affected by an authority vulnerability allowing users access to SYSTEM.AUTH.DATA.QUEUE.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1713?
CVE-2026-1713 is classified as a medium severity vulnerability affecting IBM MQ.
How do I fix CVE-2026-1713?
To mitigate CVE-2026-1713, upgrade IBM MQ to a version that is not affected, such as 9.1.0.34 or later.
What versions of IBM MQ are affected by CVE-2026-1713?
CVE-2026-1713 affects IBM MQ versions 9.1.0.0 through 9.1.0.33, 9.2.0.0 through 9.2.0.40, 9.3.0.0 through 9.3.0.36, and specific builds of 9.4.0.
What type of vulnerability is CVE-2026-1713?
CVE-2026-1713 is an authority vulnerability that may allow unauthorized access to certain functionalities within IBM MQ.
Is there a workaround for CVE-2026-1713?
There are no documented workarounds for CVE-2026-1713 other than upgrading to a secure version of IBM MQ.