CVE-2026-11726

8.1

IBM · MQ for HPE NonStop

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 is vulnerable to an out-of-bounds read due to improper validation of message header offset values, potentially leading to information disclosure or a DoS.

Executive summary

An authenticated attacker can exploit a vulnerability in IBM MQ for HPE NonStop to access sensitive information or trigger a denial of service condition.

Vulnerability

The vulnerability is an out-of-bounds read (CWE-125) caused by improper validation of message header offset values. This flaw allows an authenticated attacker to read sensitive memory or crash the service.

Business impact

Successful exploitation allows an authenticated user to gain unauthorized access to sensitive data or disrupt critical messaging services. Given the CVSS score of 8.1, this is a high-severity issue that poses a significant risk to operational availability and data confidentiality. Organizations relying on this platform for internal communication may face service outages or data leakage if this flaw is not addressed.

Remediation

Immediate Action: Upgrade to CSU 8.1.0.41 as recommended by IBM to resolve the underlying out-of-bounds read vulnerability.

Proactive Monitoring: Monitor system logs for unusual error patterns or service crashes that may indicate an attempt to manipulate message headers.

Compensating Controls: Ensure that access to the MQ environment is strictly limited to authorized personnel to reduce the attack surface for this authenticated vulnerability.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a high risk to the confidentiality and availability of IBM MQ deployments on HPE NonStop. Because the fix is readily available via the vendor, security teams should prioritize the installation of CSU 8.1.0.41 across all affected production and development environments to mitigate the potential for information disclosure and denial of service.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources