CVE-2026-12351 PUBLISHED

IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection

Assigner: ibm
Reserved: 15.06.2026 Published: 15.09.2026 Updated: 16.09.2026

IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor IBM
Product MQ
Versions
  • affected from 9.3.0.0 to 9.3.0.41 LTS (incl.)
  • affected from 9.3.0.0 to 9.3.5.1 CD (incl.)
  • affected from 9.4.0.0 to 9.4.0.25 LTS (incl.)
  • affected from 9.4.0.0 to 9.4.5.1 LTS (incl.)
  • Version 10.0.0.0 is affected

Solutions

IBM strongly recommends addressing the vulnerability now.

This issue was addressed under known issue DT473754

IBM MQ version 9.3 LTS

Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts  9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts

IBM MQ version 9.4 LTS

Apply cumulative security update 9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts

IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0

Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100

References

Problem Types

  • CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE