Junglewise Threat Intelligence

CVE-2026-12351: IBM MQ remote code execution via JNDI injection

CVE-2026-12351 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

IBM MQ is a message-oriented middleware platform used for secure enterprise application integration and messaging across distributed systems. A JNDI injection vulnerability in the Jakarta Resource Adapter IVT servlet allows unauthenticated remote attackers to execute arbitrary code on the hosting application server. This could enable complete compromise of systems running affected versions, including data theft, system manipulation, and lateral movement within networks.

Technical details

The vulnerability is a JNDI injection flaw (CWE-74: Improper Neutralization of Special Elements in Output) in IBM MQ's Jakarta Resource Adapter IVT component that processes unsafe JNDI lookups. The vulnerability is triggered when the IVT application is deployed and requires no authentication or user interaction, making it remotely exploitable over the network. An unauthenticated attacker can inject malicious JNDI references to execute arbitrary code with the privileges of the application server. IBM has released cumulative security updates for LTS versions (9.3.0.42, 9.4.0.26) and version 10.0.0.5 to address this issue.

Affected products

  • IBM MQ 9.3.0.0 through 9.3.0.41 LTS; 9.3.0.0 through 9.3.5.1 CD; 9.4.0.0 through 9.4.0.25 LTS; 9.4.0.0 through 9.4.5.1 LTS; 10.0.0.0

Timeline

  • 2026-09-14: disclosed: Initial publication of IBM security bulletin
  • 2026-09-14: patched: Cumulative security updates released: MQ 9.3.0.42 LTS, 9.4.0.26 LTS, 10.0.0.5

References

Related threats