Performance Degradation in IBM MQ Agent Due to Excessive Request Processing
CVE-2026-19645

6.5MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-19645?

An authenticated user can exploit a vulnerability in IBM MQ Agent by sending arbitrarily large or computationally expensive requests. This leads to extended processing times for agent workers, often exceeding ten minutes. When multiple such requests are sent simultaneously, the agent worker pool becomes exhausted, significantly degrading performance or causing complete unavailability of the AI Agent feature for other users.

Affected Version(s)

MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.