CVE-2026-10030 PUBLISHED

IBM MQ Console is vulnerable to privilege escalation

Assigner: ibm
Reserved: 28.05.2026 Published: 18.09.2026 Updated: 18.09.2026

IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CVSS Score: 7.1

Product Status

Vendor IBM
Product MQ
Versions
  • affected from 9.3.0.0 to 9.3.0.41 LTS (incl.)
  • affected from 9.3.0.0 to 9.3.5.1 CD (incl.)
  • affected from 9.4.0.0 to 9.4.0.25 LTS (incl.)
  • affected from 9.4.0.0 to 9.4.5.1 CD (incl.)
  • Version 10.0.0.0 is affected

Solutions

This issue was addressed under Known Issue DT472093 IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 IBM MQ version 9.4 LTS Apply cumulative security update 9.4.0.26 IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5

References

Problem Types

  • CWE-285 Improper Authorization CWE