CVE-2026-11729
Received
Received - Intake
IBM MQ Unsafe Deserialization Leading to JNDI Injection
Vulnerability report for CVE-2026-11729, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-15
Last updated on: 2026-09-15
Assigner: IBM Corporation
Description
Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | mq | From 9.1.0.0 (inc) to 9.1.0.37 (inc) |
| ibm | mq | From 9.2.0.0 (inc) to 9.2.0.43 (inc) |
| ibm | mq | From 9.3.0.0 (inc) to 9.3.0.41 (inc) |
| ibm | mq | From 9.3.0.0 (inc) to 9.3.5.1 (inc) |
| ibm | mq | From 9.4.0.0 (inc) to 9.4.0.25 (inc) |
| ibm | mq | From 9.4.0.0 (inc) to 9.4.5.1 (inc) |
| ibm | mq | 10.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |