CVE-2026-10575
8.8IBM · MQ
IBM MQ contains a heap-based buffer overflow vulnerability in the MQPUT operation that allows authenticated attackers to cause a denial of service or escalate privileges.
Executive summary
An authenticated attacker can exploit a heap buffer overflow in IBM MQ to crash services or achieve unauthorized privilege escalation.
Vulnerability
This is a heap-based buffer overflow (CWE-122) triggered during the processing of malformed distribution headers within MQPUT operations. The flaw requires the attacker to have valid, low-level authentication to the system to submit the crafted headers.
Business impact
Successful exploitation poses a significant risk to organizational stability and data integrity. With a CVSS score of 8.8, the vulnerability allows for total compromise of the affected service, potentially leading to unauthorized privilege escalation or complete system denial of service. This could cause severe disruption to messaging middleware that acts as the backbone for enterprise applications.
Remediation
Immediate Action: Update IBM MQ to the respective fixed releases, specifically 9.1.0.38, 9.2.0.44, 9.3.0.42, or the corresponding security update for your specific version branch as documented in the IBM security advisory.
Proactive Monitoring: Review IBM MQ access logs for anomalous MQPUT operations or frequent application crashes that may indicate exploitation attempts.
Compensating Controls: Ensure that access to the MQ environment is strictly limited to authorized users and implement network segmentation to reduce the attack surface for internal threats.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the High severity of this flaw and the potential for privilege escalation, administrators must prioritize the application of the vendor-provided cumulative security updates. Please consult the official IBM support documentation linked in the enrichment data to identify the exact patch required for your specific deployment environment.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section