Junglewise Threat Intelligence

CVE-2026-11378: IBM MQ integer overflow in distribution list processing

CVE-2026-11378 · Severity: high · CVSS 8.8 · Published 2026-09-18

Technologies: IBM Mq. Vendors: IBM.

Executive brief

IBM MQ is a message queue manager used by enterprises to handle message routing and application integration. An authenticated attacker can exploit an integer overflow vulnerability in distribution list processing to write to arbitrary memory locations, leading to denial of service or remote code execution on the affected queue manager.

Technical details

An integer overflow in the queue manager's object descriptor conversion allows authenticated attackers to write zeros to arbitrary heap memory locations via distribution list processing. Attack requires network access and prior authentication. Successful exploitation results in remote code execution or denial of service.

Affected products

  • IBM MQ 9.1.0.0 to 9.1.0.37 LTS, 9.2.0.0 to 9.2.0.43 LTS, 9.3.0.0 to 9.3.0.41 LTS, 9.3.0.0 to 9.3.5.1 CD, 9.4.0.0 to 9.4.0.25 LTS, 9.4.0.0 to 9.4.5.1 CD, 10.0.0.0

Timeline

  • 2026-09-14: disclosed

References

Related threats