Junglewise Threat Intelligence

CVE-2026-11725: IBM MQ integer overflow in MQINQ request

CVE-2026-11725 · Severity: high · CVSS 8.8 · Published 2026-09-18

Technologies: IBM Mq. Vendors: IBM.

Executive brief

IBM MQ is a message queueing system used by enterprises to route and deliver messages between applications. An authenticated attacker could exploit an integer overflow in the MQINQ request processor to crash the queue manager (denial of service) or execute arbitrary code with queue manager privileges, potentially compromising the entire messaging infrastructure.

Technical details

An integer overflow in IBM MQ's MQINQ request validation allows an authenticated network attacker to trigger memory corruption. The vulnerability requires existing authentication credentials and network access to the queue manager, but no user interaction. Successful exploitation grants arbitrary code execution in the context of the queue manager process.

Affected products

  • IBM MQ 9.1.0.0 to 9.1.0.37 LTS
  • IBM MQ 9.2.0.0 to 9.2.0.43 LTS
  • IBM MQ 9.3.0.0 to 9.3.0.41 LTS
  • IBM MQ 9.3.0.0 to 9.3.5.1 CD
  • IBM MQ 9.4.0.0 to 9.4.0.25 LTS
  • IBM MQ 9.4.0.0 to 9.4.5.1 CD
  • IBM MQ 10.0.0.0

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixes available: MQ 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26 LTS; 10.0.0.5 for CD and latest

References

Related threats