CVE-2026-11726 PUBLISHED

IBM MQ for HPE NonStop is vulnerable to a denial of service issue

Assigner: ibm
Reserved: 09.06.2026 Published: 18.09.2026 Updated: 18.09.2026

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS Score: 8.1

Product Status

Vendor IBM
Product MQ for HPE NonStop
Versions
  • affected from 8.1.0 to 8.1.0.40 (incl.)

Solutions

IBM MQ V8.1 for HPE NonStop 8.1.0.40IT49920 Upgrade to CSU 8.1.0.41 https://www.ibm.com/support/fixcentral/swg/selectFixes

IBM strongly recommends addressing this vulnerability now by installing CSU 8.1.0.41.

References

Problem Types

  • CWE-125 Out-of-bounds Read CWE