CVE-2026-12354
Received
Received - Intake
IBM MQ JNDI Name Validation Remote Code Execution
Vulnerability report for CVE-2026-12354, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-15
Last updated on: 2026-09-15
Assigner: IBM Corporation
Description
Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | mq | From 9.1.0.0 (inc) to 9.1.0.37 (inc) |
| ibm | mq | From 9.2.0.0 (inc) to 9.2.0.43 (inc) |
| ibm | mq | From 9.3.0.0 (inc) to 9.3.0.41 (inc) |
| ibm | mq | From 9.3.0.0 (inc) to 9.3.5.1 (inc) |
| ibm | mq | From 9.4.0.0 (inc) to 9.4.0.25 (inc) |
| ibm | mq | From 9.4.0.0 (inc) to 9.4.5.1 (inc) |
| ibm | mq | 10.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-913 | The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements. |