MQ vulnerability

IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.

Published 18 Sep 2026Updated 19 Sep 20261 sources
CVSS 7.5

What happened

IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.

Affected versions

MQ: 9.1.0.0 through 9.1.0.37 LTS (semver); 9.2.0.0 through 9.2.0.43 LTS (semver); 9.3.0.0 through 9.3.0.41 LTS (semver); 9.3.0.0 through 9.3.5.1 CD (semver); 9.4.0.0 through 9.4.0.25 LTS (semver); 9.4.0.0 through 9.4.5.1 CD (semver); 10.0.0.0 Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.