CVE-2026-11725

Summary

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

Affected Software

VendorProductVersion RangeStatus
IBMMQ9.1.0.0 <= 9.1.0.37 LTSaffected
IBMMQ9.2.0.0 <= 9.2.0.43 LTSaffected
IBMMQ9.3.0.0 <= 9.3.0.41 LTSaffected
IBMMQ9.3.0.0 <= 9.3.5.1 CDaffected
IBMMQ9.4.0.0 <= 9.4.0.25 LTSaffected
IBMMQ9.4.0.0 <= 9.4.5.1 CDaffected
IBMMQ10.0.0.0affected

Weaknesses

  • CWE-190: CWE-190 Integer Overflow or Wraparound

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References