{"api_version":"1","generated_at":"2026-09-20T17:39:12+00:00","cve":"CVE-2026-10030","urls":{"html":"https://cve.report/CVE-2026-10030","api":"https://cve.report/api/cve/CVE-2026-10030.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-10030","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-10030"},"summary":{"title":"IBM MQ Console is vulnerable to privilege escalation","description":"IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-09-18 16:17:04","updated_at":"2026-09-18 18:17:47"},"problem_types":["CWE-285","CWE-285 CWE-285 Improper Authorization"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7284894","name":"https://www.ibm.com/support/pages/node/7284894","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-10030","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10030","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"MQ","version":"affected 9.3.0.0 9.3.0.41 LTS semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"MQ","version":"affected 9.3.0.0 9.3.5.1 CD semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"MQ","version":"affected 9.4.0.0 9.4.0.25 LTS semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"MQ","version":"affected 9.4.0.0 9.4.5.1 CD semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"MQ","version":"affected 10.0.0.0","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"This issue was addressed under Known Issue DT472093\nIBM MQ version 9.3 LTS\nApply cumulative security update 9.3.0.42\nIBM MQ version 9.4 LTS\nApply cumulative security update 9.4.0.26\nIBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0\nUpgrade to IBM MQ version 10.0.0.5","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"10030","cve":"CVE-2026-10030","epss":"0.002260000","percentile":"0.135620000","score_date":"2026-09-19","updated_at":"2026-09-20 00:14:30"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-10030","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-18T16:22:46.518576Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-18T16:30:47.384Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*"],"product":"MQ","vendor":"IBM","versions":[{"lessThanOrEqual":"9.3.0.41 LTS","status":"affected","version":"9.3.0.0","versionType":"semver"},{"lessThanOrEqual":"9.3.5.1 CD","status":"affected","version":"9.3.0.0","versionType":"semver"},{"lessThanOrEqual":"9.4.0.25 LTS","status":"affected","version":"9.4.0.0","versionType":"semver"},{"lessThanOrEqual":"9.4.5.1 CD","status":"affected","version":"9.4.0.0","versionType":"semver"},{"status":"affected","version":"10.0.0.0"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.</p>"}],"value":"IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-285","description":"CWE-285 Improper Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-18T15:47:15.484Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7284894"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>This issue was addressed under Known Issue DT472093</p><p>IBM MQ version 9.3 LTS</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts\" rel=\"noopener noreferrer nofollow\">Apply cumulative security update 9.3.0.42</a></p><p>IBM MQ version 9.4 LTS</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts\" rel=\"noopener noreferrer nofollow\">Apply cumulative security update</a><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts\" rel=\"noopener noreferrer nofollow\"> 9.4.0.26</a></p><p>IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-100\" rel=\"noopener noreferrer nofollow\">Upgrade to IBM MQ version 10.0.0.5</a></p>"}],"value":"This issue was addressed under Known Issue DT472093\nIBM MQ version 9.3 LTS\nApply cumulative security update 9.3.0.42\nIBM MQ version 9.4 LTS\nApply cumulative security update 9.4.0.26\nIBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0\nUpgrade to IBM MQ version 10.0.0.5"}],"title":"IBM MQ Console is vulnerable to privilege escalation"}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-10030","datePublished":"2026-09-18T15:47:15.484Z","dateReserved":"2026-05-28T18:33:26.331Z","dateUpdated":"2026-09-18T16:30:47.384Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-18 16:17:04","lastModifiedDate":"2026-09-18 18:17:47","problem_types":["CWE-285","CWE-285 CWE-285 Improper Authorization"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-18T16:22:46.518576Z","id":"CVE-2026-10030","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"10030","Ordinal":"1","Title":"IBM MQ Console is vulnerable to privilege escalation","CVE":"CVE-2026-10030","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"10030","Ordinal":"1","NoteData":"IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.","Type":"Description","Title":"IBM MQ Console is vulnerable to privilege escalation"}]}}}