CVE-2026-19645
Received Received - Intake

IBM MQ Agent CD Denial of Service via Session Cookie

Vulnerability report for CVE-2026-19645, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: IBM Corporation

Description

IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods β€” rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
ibm ibm_mq_agent 1.0.0
ibm ibm_mq_agent 1.0.1
ibm ibm_mq_agent 2.0.0
ibm ibm_mq_agent 2.0.1
ibm mq_agent 1.0.0
ibm mq_agent 1.0.1
ibm mq_agent 2.0.0
ibm mq_agent 2.0.1
ibm mq_agent 2.0.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated user with a valid session cookie to send large or computationally expensive requests to IBM MQ Agent CD versions 1.0.0, 1.0.1, 2.0.0, and 2.0.1. These requests can hold LLM agent workers for extended periods, causing delays from tens of seconds to over ten minutes per request. When multiple such requests are sent simultaneously, the agent worker pool becomes exhausted, leading to degraded performance or complete unavailability of the AI Agent feature for all users.

The vulnerability is classified as a denial-of-service (DoS) issue due to its impact on system availability.

Impact Analysis

If you are an IBM MQ Console user, this vulnerability can cause your AI Agent feature to become slow or completely unavailable, especially during high request loads. As an authenticated user, your ability to interact with the system may be disrupted if the worker pool is exhausted by malicious or excessive requests.

Mitigation Strategies

Upgrade IBM MQ Agent to version 2.0.2 or later to address the vulnerability. Monitor agent worker pool performance and limit concurrent requests to prevent exhaustion.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19645. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart