CVE-2026-11729: IBM MQ Java messaging is vulnerable to remote code execution
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.
Other sources
IBM MQ Java client library could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0to a version that resolves this vulnerability.Fixed in 10.0.0.5 - Configuration
For IBM MQ Java client usage, upgrade IBM MQ to the cited cumulative security update levels so the unsafe deserialization that enables JNDI injection is addressed.
IBM MQ Java client library deserialization/JNDI injection behavior = patched via the cumulative security update - Compensating control
If IBM MQ Java messaging is in use and the updates cannot be applied immediately, consult the referenced Known Issue DT473375 for interim guidance.
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Client applications using the IBM MQ Java client library in the listed affected IBM MQ release ranges are exposed. The issue affects client applications rather than being described as code execution directly on an IBM MQ server.
What does an attacker need to exploit this issue?
The attacker must be authenticated. Exploitation is network-accessible, requires low privileges, and does not require user interaction, but the attack complexity is rated high.
What is the potential impact on a compromised client application?
An authenticated attacker could execute arbitrary code in the client application through unsafe deserialization and JNDI injection. The reported impact includes high confidentiality, integrity, and availability impact, with scope changed.