Junglewise Threat Intelligence

CVE-2026-11726: IBM MQ for HPE NonStop out-of-bounds read in message header

CVE-2026-11726 · Severity: high · CVSS 8.1 · Published 2026-09-18

Technologies: IBM MQ for HPE NonStop. Vendors: IBM.

Executive brief

IBM MQ for HPE NonStop is a message queueing system used for enterprise integration in mission-critical environments. An authenticated attacker can exploit improper validation of message header offsets to read sensitive data from memory or crash the service, causing business disruptions. The vulnerability requires valid credentials to exploit but poses significant risk to confidentiality and availability.

Technical details

The vulnerability is an out-of-bounds read (CWE-125) in message header processing due to improper validation of header offset values. Attack vector is network-based, requires authentication (PR:L), and no user interaction. An attacker can trigger information disclosure or denial of service. A patch is available via CSU 8.1.0.41.

Affected products

  • IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: CSU 8.1.0.41 available

References

Related threats