IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.
Advisories

No advisories yet.

Fixes

Solution

This issue was addressed under Known Issue DT472093 IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 IBM MQ version 9.4 LTS Apply cumulative security update 9.4.0.26 IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5


Workaround

No workaround given by the vendor.

History

Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.
Title IBM MQ Console is vulnerable to privilege escalation
First Time appeared Ibm
Ibm mq
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T16:30:47.384Z

Reserved: 2026-05-28T18:33:26.331Z

Link: CVE-2026-10030

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:04.020

Modified: 2026-09-18T18:17:47.257

Link: CVE-2026-10030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses