CVE-2026-11378 PUBLISHED

IBM MQ queue manager is vulnerable to remote code execution

Assigner: ibm
Reserved: 05.06.2026 Published: 18.09.2026 Updated: 19.09.2026

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor IBM
Product MQ
Versions
  • affected from 9.1.0.0 to 9.1.0.37 LTS (incl.)
  • affected from 9.2.0.0 to 9.2.0.43 LTS (incl.)
  • affected from 9.3.0.0 to 9.3.0.41 LTS (incl.)
  • affected from 9.3.0.0 to 9.3.5.1 CD (incl.)
  • affected from 9.4.0.0 to 9.4.0.25 LTS (incl.)
  • affected from 9.4.0.0 to 9.4.5.1 CD (incl.)
  • Version 10.0.0.0 is affected

Solutions

This issue was addressed under Known Issue DT473420

IBM MQ version 9.1 LTS

Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts

IBM MQ version 9.2 LTS

Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts

IBM MQ version 9.3 LTS

Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts

IBM MQ version 9.4 LTS

Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts

IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0

Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100

References

Problem Types

  • CWE-190 Integer Overflow or Wraparound CWE