CVE-2026-12351
Received Received - Intake

Remote Code Execution in IBM MQ

Vulnerability report for CVE-2026-12351, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: IBM Corporation

Description

IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
ibm mq From 9.3.0.0 (inc) to 9.3.0.41 (inc)
ibm mq From 9.3.0.0 (inc) to 9.3.5.1 (inc)
ibm mq From 9.4.0.0 (inc) to 9.4.0.25 (inc)
ibm mq From 9.4.0.0 (inc) to 9.4.5.1 (inc)
ibm mq 10.0.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a JNDI injection flaw in IBM MQ's Jakarta Resource Adapter IVT servlet. It allows remote attackers to execute arbitrary code on affected servers by exploiting unsafe JNDI lookup processing when the IVT application is deployed. The issue is classified under CWE-74 and affects multiple IBM MQ versions.

Detection Guidance

To detect this vulnerability, check if the IVT application is deployed on your IBM MQ server. Inspect the Jakarta Resource Adapter IVT servlet for JNDI injection flaws. Verify IBM MQ versions against affected ranges (9.3.0.0-9.3.0.41 LTS, 9.3.0.0-9.3.5.1 CD, 9.4.0.0-9.4.0.25 LTS, 9.4.0.0-9.4.5.1 LTS, 10.0.0.0).

  • Check deployed applications: Review application servers for the IVT servlet deployment.
  • Inspect logs: Look for unusual JNDI lookup patterns or remote code execution attempts.
Impact Analysis

This vulnerability can allow unauthenticated remote attackers to execute arbitrary code on your IBM MQ server. This could lead to full system compromise, data theft, or disruption of services if the IVT application is deployed.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules. Organizations must address this flaw to maintain compliance with these regulations.

Mitigation Strategies

Apply the latest IBM MQ fixes immediately: upgrade to 9.3.0.42 LTS, 9.4.0.26 LTS, or IBM MQ 10.0.0.5 for CD versions. Remove or disable the IVT application if not required. Ensure network segmentation to limit exposure.

  • Install cumulative security updates for affected versions.
  • Upgrade to IBM MQ 10.0.0.5 if using 9.3 CD, 9.4 CD, or 10.0.0.0.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12351. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart