CVE-2026-1713
IBM WebSphere MQ vulnerability analysis and mitigation

Overview

CVE-2026-1713 is an authentication bypass vulnerability (CWE-305) in IBM MQ that allows a low-privileged local user to modify or tamper with MQ data and configurations when user interaction is present. It affects IBM MQ versions 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.17 LTS, and 9.4.0.0 through 9.4.4.1 CD. The vulnerability was published on March 3, 2026, with a patch made available shortly after. It carries a CVSS v3.1 base score of 5.0 (Medium) (IBM Support, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-305 (Authentication Bypass by Primary Weakness), meaning a secondary authentication or authorization control can be circumvented due to a weakness in a primary mechanism. The attack vector is local, requiring low privileges and user interaction, with low attack complexity. A local attacker with limited privileges can exploit this flaw to bypass authentication controls within IBM MQ, enabling unauthorized modification of messaging data and system configurations. No public technical write-ups or proof-of-concept code have been identified at this time (IBM Support, Red Hat CVE).

Impact

Successful exploitation of CVE-2026-1713 allows a low-privileged local attacker to compromise the integrity of IBM MQ messaging data and configurations, potentially disrupting message routing, altering queue configurations, or injecting malicious messages into business-critical workflows. Confidentiality and availability are not impacted by this vulnerability. The scope is limited to the affected MQ instance, but integrity compromise of a messaging backbone could have downstream effects on dependent applications and services (IBM Support).

Mitigation and workarounds

IBM has released patched versions addressing CVE-2026-1713. Organizations should upgrade to one of the following fixed releases based on their deployment track: IBM MQ 9.1.0.34 LTS or later, 9.2.0.41 LTS or later, 9.3.0.37 LTS or later, 9.4.0.20 LTS or later, or 9.4.5.0 CD or later. As interim measures, apply the principle of least privilege to restrict local system access, limit user interactions with MQ systems to authorized personnel, and monitor MQ systems for unauthorized configuration or data modifications (IBM Support).

Additional resources


SourceThis report was generated using AI

Related IBM WebSphere MQ vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-36128HIGH7.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesOct 16, 2025
CVE-2025-36100MEDIUM5.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesSep 07, 2025
CVE-2025-0985MEDIUM5.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • mq
NoYesFeb 28, 2025
CVE-2024-54175MEDIUM5.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesFeb 28, 2025
CVE-2026-1713MEDIUM5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesMar 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management