CVE-2026-10747
IBM MQ pre-auth heap overflow in protocol message processing
IBM scored CVE-2026-10747 CVSS 3.1 10.0 for a heap buffer overflow in MQ protocol message processing before authentication. An unauthenticated remote attacker with access to the listener can cause denial of service or potentially execute code. Fixed in MQ CSUs such as 9.4.0.26 and 10.0.0.5. Not in CISA KEV.
- CVSS
- 10
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Class
- RCE
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- IBM
- Products
- IBM MQ, IBM MQ Appliance
- Affected
- IBM MQ Server: 9.1.0.0–9.1.0.37 LTS; 9.2.0.0–9.2.0.43 LTS; 9.3.0.0–9.3.0.41 LTS; 9.3.0.0–9.3.5.1 CD; 9.4.0.0–9.4.0.25 LTS; 9.4.0.0–9.4.5.1 CD; 10.0.0.0. IBM MQ Appliance: 9.4.0.0–9.4.0.25 LTS; 9.4.1.0–9.4.5.2 CD; 10.0.0.0–10.0.0.1.
- Fixed
- IBM MQ: CSU 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26 LTS; CD streams upgrade to 10.0.0.5. IBM MQ Appliance: 9.4.0.26 LTS; 9.4.5.3 (M2002 CD); 10.0.0.5 (M2003 CD and 10 LTS). APAR DT472411. No workarounds listed.
- CWE
- CWE-122
- Published
- 18 Sept 2026
- Updated
- 5 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-10747 is a heap-based buffer overflow in IBM MQ protocol message processing before authentication. IBM’s MQ Server bulletin says an unauthenticated remote attacker with network access to the listener port could execute arbitrary code. The same CVE is covered for IBM MQ Appliance. IBM classifies the weakness as CWE-122 and publishes CVSS 3.1 score 10.0 with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. NVD lists that score from psirt@us.ibm.com as Secondary and marks the entry Awaiting Analysis. Impact language is denial of service or potentially arbitrary code execution.
Affected IBM MQ Server ranges in the bulletin include 9.1 through 9.4 LTS/CD builds up to the versions named above and 10.0.0.0; only the Server installable component is called out. Appliance ranges include 9.4 LTS through 9.4.0.25, 9.4 CD through 9.4.5.2, and 10.0.0.0–10.0.0.1. Remediation is under APAR DT472411: CSUs 9.1.0.38, 9.2.0.44, 9.3.0.42, and 9.4.0.26 for LTS; CD customers upgrade to 10.0.0.5; Appliance customers apply 9.4.0.26, 9.4.5.3, or 10.0.0.5 as listed. IBM lists no workarounds.
CISA has not added the CVE to KEV; CISA SSVC sets exploitation to none. ThreatWire found no public PoC repository for this CVE id. Exploitation in the wild is not confirmed.