CVE-2026-12351: IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection
IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.
Other sources
IBM MQ Jakarta Resource Adapter IVT could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch DT473754 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 10.0to a version that resolves this vulnerability.Fixed in 10.0.0.5
Event History
Frequently Asked Questions
Which deployments are exposed to remote exploitation?
The issue applies when the IVT application is deployed, including the IBM MQ Jakarta Resource Adapter IVT. The listed affected IBM MQ releases are 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0.
Does exploitation require authentication or user interaction?
No. The vulnerability is rated AV:N/AC:L/PR:N/UI:N, indicating it can be exploited remotely with low attack complexity, without privileges or user interaction.
What is the impact if exploitation succeeds?
A remote attacker could execute arbitrary code. The supplied severity vector indicates high confidentiality, integrity, and availability impact.