CVE-2026-11725

8.8

IBM · MQ

IBM MQ contains an integer overflow vulnerability in MQINQ request processing, which may allow an authenticated attacker to trigger a denial of service or execute arbitrary code.

Executive summary

An integer overflow vulnerability in IBM MQ allows authenticated attackers to potentially execute arbitrary code or cause a service disruption.

Vulnerability

The vulnerability is an integer overflow (CWE-190) occurring during the processing of MQINQ requests. This flaw requires the attacker to have authenticated access to the system to successfully trigger the overflow condition.

Business impact

Successful exploitation of this vulnerability could lead to a complete loss of confidentiality, integrity, and availability within the affected MQ environment. Given the high CVSS score of 8.8, this flaw represents a significant risk to enterprise messaging backbones, potentially enabling attackers to escalate privileges or disrupt critical business communication workflows.

Remediation

Immediate Action: Apply the relevant cumulative security updates provided by IBM for your specific LTS or CD release, such as versions 9.1.0.38, 9.2.0.44, or 9.3.0.42.

Proactive Monitoring: Monitor MQ access logs for abnormal MQINQ request patterns or repeated service crashes that may indicate exploitation attempts.

Compensating Controls: Ensure that access to the MQ infrastructure is strictly limited to authorized users and implement network segmentation to reduce the attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing IBM MQ must prioritize the deployment of the provided security patches. Given the potential for arbitrary code execution and the high severity rating, testing and deploying these updates should be integrated into the immediate patch management cycle to prevent unauthorized system compromise.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources