Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Published: 2026-09-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM MQ is vulnerable due to a flaw that allows a remote authenticated attacker to deserialise untrusted data and execute arbitrary code on the host. The weakness is caused by insecure handling of deserialized objects valid credentials to inject malicious payloads and gain full control of the system.

Affected Systems

Versions of IBM MQ from 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS and CD, 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS and CD, 9.4.5.1 CD, and 10.0.0.0 are affected. The vulnerability applies to all builds within these major releases, including both long‑term support and current development builds.

Risk and Exploitability

The CVSS score of 8.8 indicates high impact with medium‑to‑high likelihood for a successful exploit. The EPSS score is under 1%, indicating a very low but non‑zero probability of exploitation, although the precise exploitation frequency remains unclear. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over the MQ network when an authenticated client submits a crafted payload; the prerequisite is a valid user credential. An attacker who succeeds could execute arbitrary code on the MQ server, potentially leading to full system compromise.

Generated by OpenCVE AI on September 17, 2026 at 19:19 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT474598 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the cumulative security update for the IBM MQ major release in use (e.g., 9.1.0.38 for 9.1 LTS, 9.2.0.44 for 9.2 LTS, 9.3.0.42 for 9.3 LTS, 9.4.0.26 for 9.4 LTS, or upgrade to 10.0.0.5 for the 10.0.0.0 build, 9.3‑CD, or 9.4‑CD).
  • Reconfigure MQ to restrict or disallow deserialization of untrusted data by adjusting serialization settings or applying application‑level validation, thereby ensuring that only trusted objects are processed.
  • Enforce strong authentication and apply network segmentation so that only privileged, authenticated users can access MQ services, reducing the attack surface for malicious payload delivery.

Generated by OpenCVE AI on September 17, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Title IBM MQ Java messaging is vulnerable to remote code execution
First Time appeared Ibm
Ibm mq
Weaknesses CWE-502
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-16T03:56:16.677Z

Reserved: 2026-06-24T22:01:19.695Z

Link: CVE-2026-13293

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:41.835Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:02.130

Modified: 2026-09-16T19:21:55.793

Link: CVE-2026-13293

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data