CVE-2026-19645
Received
Received - Intake
IBM MQ Agent CD Denial of Service via Session Cookie
Vulnerability report for CVE-2026-19645, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-04
Last updated on: 2026-09-04
Assigner: IBM Corporation
Description
Description
IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods β rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | ibm_mq_agent | 1.0.0 |
| ibm | ibm_mq_agent | 1.0.1 |
| ibm | ibm_mq_agent | 2.0.0 |
| ibm | ibm_mq_agent | 2.0.1 |
| ibm | mq_agent | 1.0.0 |
| ibm | mq_agent | 1.0.1 |
| ibm | mq_agent | 2.0.0 |
| ibm | mq_agent | 2.0.1 |
| ibm | mq_agent | 2.0.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |