
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-10030 is an improper authorization vulnerability in the IBM MQ Console that allows authenticated non-administrative users to create and start queue managers. The flaw affects IBM MQ versions 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0. It was published on September 18, 2026, with a patch made available the same day. The vulnerability carries a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory).
The root cause is classified as CWE-285 (Improper Authorization): the IBM MQ Console fails to correctly enforce authorization checks when non-administrative authenticated users attempt to perform privileged operations such as creating and starting queue managers. The attack vector is network-based, requires low privileges (a valid authenticated session), no user interaction, and low attack complexity, making it straightforward to exploit for any user with console access. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, IBM Advisory).
Successful exploitation allows any authenticated non-administrative user to create and start queue managers within the IBM MQ environment, resulting in high availability impact and low integrity impact with no confidentiality impact. This could disrupt message queue operations, cause service outages for dependent applications, and potentially allow an attacker to introduce rogue queue managers that interfere with legitimate message routing. The NVD SSVC assessment characterizes the technical impact as partial and notes the vulnerability is not automatable (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code as of the disclosure date. The EPSS score is 0.0, indicating a very low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated session to the IBM MQ Console, limiting the attack surface to users who already have some level of access (GitHub Advisory).
IBM has released a patch addressing this vulnerability, referenced in the IBM support advisory (node 7284894). Organizations should apply the available patch immediately for all affected versions (IBM MQ 9.3.x LTS/CD, 9.4.x LTS/CD, and 10.0.0.0). As an interim workaround, restrict IBM MQ Console access to administrative users only and implement network-level access controls to limit console connectivity to trusted administrative networks (IBM Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."