Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution on the application server
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Resource Adapter Installation Verification Test application of IBM MQ. Incorrect validation of JNDI names allows an attacker who has authenticated access to supply a crafted name that causes the application server to resolve and load untrusted code. This flaw is classified as CWE‑913 and can lead to arbitrary code execution with the privileges of the application server, compromising confidentiality, integrity, and availability of the affected environment.

Affected Systems

IBM MQ versions from 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 are affected. IBM provides cumulative security updates for each major LTS release—9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26—and recommends upgrading to IBM MQ 10.0.0.5 for systems still running 10.0.0.0 or CD builds.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while an EPSS of less than 1% suggests a very low exploitation likelihood under current conditions. Although not yet listed in the CISA KEV catalog, the vulnerability remains a significant threat for installations that have not applied the fix because it requires only legitimate authenticated access—which is common in many MQ deployments—and can immediately lead to complete server compromise. There is no publicly documented exploit, but the remote code execution path demonstrates the potential for severe impact if an attacker gains proper credentials.

Generated by OpenCVE AI on September 20, 2026 at 15:07 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT473753 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the IBM MQ 9.1 LTS cumulative security update 9.1.0.38 to all 9.1 installations.
  • Apply the IBM MQ 9.2 LTS cumulative security update 9.2.0.44 to all 9.2 installations.
  • Apply the IBM MQ 9.3 LTS cumulative security update 9.3.0.42 to all 9.3 LTS installations.
  • Apply the IBM MQ 9.4 LTS cumulative security update 9.4.0.26 to all 9.4 LTS installations.
  • For systems running IBM MQ 9.3 CD, 9.4 CD, or 10.0.0.0, upgrade to IBM MQ 10.0.0.5.
  • Reduce the privilege level of the Resource Adapter Installation Verification Test application and restrict JNDI name usage until the patch is applied to prevent exploitation if the vulnerability is not immediately patched.

Generated by OpenCVE AI on September 20, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.
Title IBM MQ Resource Adapter IVT message-driven bean is vulnerable to remote code execution via JNDI injection
First Time appeared Ibm
Ibm mq
Weaknesses CWE-913
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-16T03:56:36.302Z

Reserved: 2026-06-15T21:42:00.609Z

Link: CVE-2026-12354

cve-icon Vulnrichment

Updated: 2026-09-15T19:02:33.441Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:13.847

Modified: 2026-09-16T19:21:55.793

Link: CVE-2026-12354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:15:17Z

Weaknesses
  • CWE-913

    Improper Control of Dynamically-Managed Code Resources