CVE-2026-10751: IBM MQ Java messaging is vulnerable to remote code execution
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0.0.0to a version that resolves this vulnerability.Fixed in 10.0.0.5 - Compensating control
If you cannot upgrade immediately, address the vulnerability referenced as deserialization filter bypass in exception handling in IBM MQ Java/JMS client libraries (issue addressed under Known Issue DT472667).
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker must be authenticated and able to target an application using the IBM MQ Java or JMS client libraries. Exploitation is remote, requires low privileges, and does not require user interaction.
What is the potential impact on a vulnerable client application?
A successful exploit could allow arbitrary code execution on the client application. The stated impact includes high confidentiality, integrity, and availability consequences.
Which component should teams prioritize when assessing exposure?
Assess applications that use IBM MQ Java or JMS client libraries, particularly their exception-handling paths. The issue is described as a deserialization filter bypass in exception handling rather than a general statement about all IBM MQ components.