CVE-2026-10575

8.8

IBM · MQ

IBM MQ contains a heap-based buffer overflow vulnerability in the MQPUT operation that allows authenticated attackers to cause a denial of service or escalate privileges.

Executive summary

An authenticated attacker can exploit a heap buffer overflow in IBM MQ to crash services or achieve unauthorized privilege escalation.

Vulnerability

This is a heap-based buffer overflow (CWE-122) triggered during the processing of malformed distribution headers within MQPUT operations. The flaw requires the attacker to have valid, low-level authentication to the system to submit the crafted headers.

Business impact

Successful exploitation poses a significant risk to organizational stability and data integrity. With a CVSS score of 8.8, the vulnerability allows for total compromise of the affected service, potentially leading to unauthorized privilege escalation or complete system denial of service. This could cause severe disruption to messaging middleware that acts as the backbone for enterprise applications.

Remediation

Immediate Action: Update IBM MQ to the respective fixed releases, specifically 9.1.0.38, 9.2.0.44, 9.3.0.42, or the corresponding security update for your specific version branch as documented in the IBM security advisory.

Proactive Monitoring: Review IBM MQ access logs for anomalous MQPUT operations or frequent application crashes that may indicate exploitation attempts.

Compensating Controls: Ensure that access to the MQ environment is strictly limited to authorized users and implement network segmentation to reduce the attack surface for internal threats.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the High severity of this flaw and the potential for privilege escalation, administrators must prioritize the application of the vendor-provided cumulative security updates. Please consult the official IBM support documentation linked in the enrichment data to identify the exact patch required for your specific deployment environment.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources