Junglewise Threat Intelligence

CVE-2026-2607: IBM MQ sensitive information disclosure in log files

CVE-2026-2607 · Severity: medium · CVSS 5.1 · Published 2026-05-27

Vendors: IBM.

Executive brief

IBM MQ, a messaging middleware used to integrate applications and data across different platforms, is affected by a vulnerability where sensitive information is recorded in log files. A local user with access to the system's logs could potentially view this sensitive data, leading to unauthorized information disclosure. This could compromise the security of the messaging environment or provide a foothold for further attacks.

Technical details

IBM MQ and the IBM MQ Operator are vulnerable to information disclosure due to the insertion of sensitive information into log files (CWE-532). The vulnerability exists in various versions of the MQ Operator and MQ Advanced container images across Continuous Delivery (CD) and Long Term Support (LTS) release streams. An attacker with local access to the system or the container environment could read these log files to extract potentially sensitive data. The attack complexity is considered high, likely because it requires specific timing or access to logs that may be restricted under certain configurations. Users are advised to refer to the IBM security bulletin for specific patch versions and remediation steps.

Affected products

  • IBM MQ Operator 3.2.0 - 3.2.23, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 - 3.5.3, 3.6.0 - 3.6.4, 3.7.0 - 3.7.2, 3.8.0, 3.8.1, 3.9.0, 3.9.1, 2.0.0 - 2.0.29 (LTS)
  • IBM MQ Advanced container images 9.4.0.6 - 9.4.0.20, 9.4.1.0 - 9.4.5.0 (CD), 9.3.0.0 - 9.3.0.25 (LTS), 9.4.0.0 - 9.4.0.5 (LTS)

Timeline

  • 2026-05-27: disclosed: Initial publication of the vulnerability advisory.
  • 2026-05-27: advisory: IBM published the security bulletin.

References