Description
IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

IBM MQ can allow a remote attacker to execute arbitrary code by exploiting unsafe JNDI lookup processing when the IVT application is deployed. The flaw permits unauthenticated attackers to run code on the host, compromising confidentiality, integrity, and availability with no user interaction. The weakness is a form of input manipulation (CWE-74).

Affected Systems

The affected products are IBM MQ versions 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0. IBM recommends applying the 9.3.0.42 cumulative security update to all 9.3 LTS installations, the 9.4.0.26 update to all 9.4 LTS installations, and upgrading 9.3 CD, 9.4 CD, and 10.0.0.0 installations to IBM MQ 10.0.0.5.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. EPSS data is not available, andV catalog, but the high impact and lack of authentication required for exploitation strongly suggest the need for immediate remediation. The likely attack vector is an unauthenticated remote JNDI injection that can be triggered by a malicious client connecting to the MQ server.

Generated by OpenCVE AI on September 16, 2026 at 01:41 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. This issue was addressed under known issue DT473754 IBM MQ version 9.3 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts  9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update 9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the IBM MQ 9.3.0.42 cumulative security update for all 9.3 LTS installations
  • Apply the IBM MQ 9.4.0.26 cumulative security update for all 9.4 LTS installations
  • Upgrade 9.3 CD, 9.4 CD, and version 10.0.0.0 installations to IBM MQ 10.0.0.5

Generated by OpenCVE AI on September 16, 2026 at 01:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.
Title IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection
First Time appeared Ibm
Ibm mq
Weaknesses CWE-74
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T18:59:28.755Z

Reserved: 2026-06-15T20:43:36.298Z

Link: CVE-2026-12351

cve-icon Vulnrichment

Updated: 2026-09-15T18:59:20.805Z

cve-icon NVD

Status : Received

Published: 2026-09-15T18:17:13.727

Modified: 2026-09-15T19:17:15.503

Link: CVE-2026-12351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:15Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')