Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is caused by unsafe deserialization of client data that allows JNDI injection. An authenticated attacker who can influence the data sent to the IBM MQ Java client can trigger execution of arbitrary code on the client system. This is a classic deserialization flaw (CWE-502) that leads to remote code execution.

Affected Systems

Affected are IBM MQ 9.1 LTS versions 9.1.0.0 through 9.1.0.37; IBM MQ 9.2 LTS 9.2.0.0 through 9.2.0.43; IBM MQ 9.3 releases 9.3.0.0 through 9.3.5.1 (CD and LTS); IBM MQ 9.4 releases 9.4.0.0 through 9.4.5.1 (CD and LTS); and IBM MQ 10.0.0.0. All affected products require Java and use the MQ Java client libraries, so any environment where a client connects to an IBM MQ broker and is authenticated is potentially vulnerable.

Risk and Exploitability

The CVSS score is 8.5, indicating high severity. The EPSS score is less than 1%, but the lack of a KEV listing suggests the vulnerability is not yet known to be exploited, yet its high impact warrants prompt action. Exploitation requires an authenticated attacker who can send crafted data to the MQ Java client, typically via a malicious JMS or other message, enabling JNDI injection and arbitrary code execution on the client host.

Generated by OpenCVE AI on September 20, 2026 at 14:50 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT473375 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the cumulative security update appropriate to your MQ version (for example, 9.1.0.38 for 9.1 LTS, 9.2.0.44 for 9.2 LTS, 9.3.0.42 for 9.3 LTS, 9.4.0.26 for 9.4 LTS, or 10.0.0.5 for 10.0.0.0).
  • If your environment uses the CD releases of versions 9.3, 9.4, or 10.0.0.0, ensure you have upgraded to the latest security releases as specified by IBM.
  • Until the patch can be applied, configure MQ clients to block or reject JNDI lookup URLs or otherwise disable JNDI lookups in client configuration to reduce the attack surface.

Generated by OpenCVE AI on September 20, 2026 at 14:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.
Title IBM MQ Java messaging is vulnerable to remote code execution
First Time appeared Ibm
Ibm mq
Weaknesses CWE-502
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-16T03:56:51.027Z

Reserved: 2026-06-09T02:37:08.660Z

Link: CVE-2026-11729

cve-icon Vulnrichment

Updated: 2026-09-15T19:02:29.313Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:12.393

Modified: 2026-09-16T19:21:55.793

Link: CVE-2026-11729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data