Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI injection attacks due to insufficient input validation, potentially leading to information disclosure or remote code execution.
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability involves improper input validation in IBM MQ's IVT servlet, allowing an attacker to inject a JNDI reference. The servlet accepts crafted input fragments without proper sanitization, which can cause the application to resolve or bind to arbitrary JNDI resources. The flaw can lead to disclosure of configuration or data, and if the attacker supplies malicious code, remote code execution is possible. This injection flaw is identified as CWE‑74.

Affected Systems

IBM MQ versions 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.5.1 (both LTS and CD), 9.4.0.0 through 9.4.5.1, and 10.0.0.0 are affected. The vulnerable IVT servlet is exposed over the network and can be accessed without authentication by an external attacker, potentially on any system running these product versions.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity with remote code execution potential. The EPSS score is reported as < 1%, reflecting a low yet non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Assuming network reachability to the IVT servlet endpoint, an attacker who can supply arbitrary request data could trigger the injection, potentially compromising the host and the MQ service. Prompt remediation is therefore recommended.

Generated by OpenCVE AI on September 20, 2026 at 15:08 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT473764 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the IBM MQ 9.1 LTS cumulative security update 9.1.0.38 to all versions 9.1.0.0‑9.1.0.37.
  • Apply the IBM MQ 9.2 LTS cumulative security update 9.2.0.44 to all versions 9.2.0.0‑9.2.0.43.
  • Apply the IBM MQ 9.3 LTS cumulative security update 9.3.0.42 to all versions 9.3.0.0‑9.3.5.1.
  • Apply the IBM MQ 9.4 LTS cumulative security update 9.4.0.26 to all versions 9.4.0.0‑9.4.5.1.
  • Upgrade IBM MQ 9.3 CD, 9.4 CD, and 10.0.0.0 to IBM MQ 10.0.0.5.

Generated by OpenCVE AI on September 20, 2026 at 15:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI injection attacks due to insufficient input validation, potentially leading to information disclosure or remote code execution.
Title IBM MQ Resource Adapter IVT servlet is vulnerable to unauthenticated remote code execution
First Time appeared Ibm
Ibm mq
Weaknesses CWE-74
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-16T03:56:37.380Z

Reserved: 2026-06-15T21:47:43.112Z

Link: CVE-2026-12355

cve-icon Vulnrichment

Updated: 2026-09-15T17:32:56.701Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:13.980

Modified: 2026-09-16T19:21:55.793

Link: CVE-2026-12355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:15:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')