Junglewise Threat Intelligence

CVE-2026-12355: IBM MQ JNDI injection in Resource Adapter IVT servlet

CVE-2026-12355 · Severity: high · CVSS 8.1 · Published 2026-09-15

Executive brief

IBM MQ is a message-oriented middleware platform used for reliable enterprise messaging. An unauthenticated attacker can exploit insufficient input validation in the Resource Adapter IVT servlet to inject malicious JNDI URLs, leading to remote code execution on the hosting application server if the IVT EAR is deployed. This could result in complete system compromise, data theft, and service disruption.

Technical details

The vulnerability is a JNDI injection flaw (CWE-74: Improper Neutralization of Special Elements in Output) in IBM MQ's JMS Resource Adapter IVT servlet. The root cause is insufficient input validation and a bypass of JNDI name sanitization. An unauthenticated, network-accessible attacker can supply a malicious JNDI URL to execute arbitrary code on the hosting application server if the IVT EAR file is deployed. No authentication or user interaction is required. Fixes are available via cumulative security updates (9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26) or upgrades to MQ 10.0.0.5 or later.

Affected products

  • IBM MQ 9.1.0.0 through 9.1.0.37 LTS
  • IBM MQ 9.2.0.0 through 9.2.0.43 LTS
  • IBM MQ 9.3.0.0 through 9.3.0.41 LTS
  • IBM MQ 9.3.0.0 through 9.3.5.1 CD
  • IBM MQ 9.4.0.0 through 9.4.0.25 LTS
  • IBM MQ 9.4.0.0 through 9.4.5.1 CD
  • IBM MQ 10.0.0.0

Timeline

  • 2026-09-14: disclosed: Initial publication

References

Related threats