Description
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An authenticated attacker can execute arbitrary code on client applications that use IBM MQ Java or JMS client libraries. The vulnerability arises from a deserialization filter bypass in exception handling, which allows malicious data to be processed without proper validation. This weakness is a classic example of CWE-502, deserialization of untrusted data.

Affected Systems

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.4 LTS, and the CD releases of 9.3, 9.4, and 10.0.0.0 are vulnerable. Patches are available for each version: cumulative security update 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and upgrading to IBM MQ 10.0.0.5 for the CD releases.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate to high severity vulnerability that can lead to full system compromise if exploited. The EPSS score is 0.5%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, but the remote code execution potential and requirement for only authenticated access make it a significant risk for organizations that run IBM MQ client applications.

Generated by OpenCVE AI on September 19, 2026 at 17:55 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT472667 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply IBM MQ cumulative security update 9.1.0.38 for version 9.1 LTS
  • Apply IBM MQ cumulative security update 9.2.0.44 for version 9.2 LTS
  • Apply IBM MQ cumulative security update 9.3.0.42 for version 9.3 LTS
  • Apply IBM MQ cumulative security update 9.4.0.26 for version 9.4 LTS
  • Upgrade IBM MQ CD releases to version 10.0.0.5
  • If an immediate update cannot be performed, restrict network access to the MQ client applications and enable strict Java deserialization filters to reject unexpected data.

Generated by OpenCVE AI on September 19, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
Title IBM MQ Java messaging is vulnerable to remote code execution
First Time appeared Ibm
Ibm mq
Weaknesses CWE-502
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-21T12:47:23.426Z

Reserved: 2026-06-03T13:55:56.568Z

Link: CVE-2026-10751

cve-icon Vulnrichment

Updated: 2026-09-21T12:45:04.415Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:04.563

Modified: 2026-09-21T13:17:07.270

Link: CVE-2026-10751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:00:13Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data