SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19645

MEDIUM · CVSS 6.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Authenticated users of IBM MQ Agent versions 1.0.0, 1.0.1, 2.0.0, and 2.0.1 can exploit this vulnerability by submitting large or resource-intensive requests, leading to significant delays and potential denial of service for other users. The impact includes degraded performance or complete unavailability of the AI Agent feature, particularly when multiple requests are made simultaneously. Organizations utilizing these versions should prioritize remediation to ensure consistent service availability and performance.

CVE
CVE-2026-19645
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%

Original NVD Description

IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature.