CVE-2026-13293: IBM MQ Java messaging is vulnerable to remote code execution
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Other sources
IBM MQ could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0to a version that resolves this vulnerability.Fixed in 10.0.0.5 - Compensating control
If patching is delayed, reference and follow the known issue mitigation provided in Known Issue DT474598 for this deserialization/remote code execution vulnerability in IBM MQ Java messaging.
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must be remotely authenticated and have low privileges. No user interaction is required.
Which IBM MQ release lines are affected?
Affected releases include 9.1.0.0 through 9.1.0.37 LTS; 9.2.0.0 through 9.2.0.43 LTS; 9.3.0.0 through 9.3.0.41 LTS and 9.3.0.0 through 9.3.5.1 CD; 9.4.0.0 through 9.4.0.25 LTS and 9.4.0.0 through 9.4.5.1 CD; and 10.0.0.0.
What is the potential impact of successful exploitation?
A successful attacker can execute arbitrary code on the affected system. The reported impact includes high confidentiality, integrity, and availability impact.