Junglewise Threat Intelligence

CVE-2026-12354: IBM MQ JNDI injection in Resource Adapter IVT

CVE-2026-12354 · Severity: high · CVSS 7.5 · Published 2026-09-15

Executive brief

IBM MQ is enterprise messaging middleware that enables application-to-application communication across the organization. The Resource Adapter Installation Verification Test (IVT) component contains a JNDI injection vulnerability that allows authenticated attackers to place malicious messages that execute arbitrary code on the application server. Successful exploitation could lead to complete system compromise, data theft, and service disruption for critical business messaging infrastructure.

Technical details

The vulnerability is a JNDI injection flaw (CWE-913) in IBM MQ's Resource Adapter IVT message-driven bean, which improperly validates dynamically-constructed JNDI names. An authenticated attacker with the ability to write messages to the IVT queue can craft a malicious message containing a crafted JNDI name that will be resolved during message processing, allowing arbitrary code execution on the hosting application server. The attack requires network access to the MQ broker, valid authentication credentials, and write access to the IVT queue. IBM has released cumulative security updates for all affected LTS and CD versions (9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and upgrades to 10.0.0.5).

Affected products

  • IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, 10.0.0.0

Timeline

  • 2026-09-14: disclosed: IBM security bulletin published
  • 2026-09-14: patched: Security updates released: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and 10.0.0.5

References

Related threats