CVE-2026-19645: Multiple vulnerabilities in IBM MQ Agent images
An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ Agent CDto a version that resolves this vulnerability.Fixed in v2.0.2 - Upgrade
Upgrade
ibm-mq-agent-embedding-serviceto a version that resolves this vulnerability.Fixed in v2.0.2 - Upgrade
Upgrade
ibm-mq-agent-mcpto a version that resolves this vulnerability.Fixed in v2.0.2 - Upgrade
Upgrade
ibm-mq-agent-runtimeto a version that resolves this vulnerability.Fixed in v2.0.2
Event History
Frequently Asked Questions
Does exploiting this issue require elevated privileges or user interaction?
The issue is rated as requiring low privileges and no user interaction. The attacker must have a valid authenticated session cookie.
Can this issue directly expose or modify data?
The supplied CVSS vector indicates no confidentiality or integrity impact. The documented impact is availability loss affecting the AI Agent feature for IBM MQ Console users.