IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature.
History

Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature.
Title Multiple vulnerabilities in IBM MQ Agent images
First Time appeared Ibm
Ibm mq Agent
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:mq_agent:cd:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq Agent
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-09-04T15:20:24.432Z

Updated: 2026-09-04T15:20:24.432Z

Reserved: 2026-08-12T17:12:34.967Z

Link: CVE-2026-19645

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T16:17:24.923

Modified: 2026-09-08T14:17:08.940

Link: CVE-2026-19645

cve-icon Redhat

No data.