Executive brief
IBM MQ is an enterprise message-oriented middleware platform used by organizations to reliably route and process business transactions across systems. A vulnerability in the Java messaging component allows authenticated attackers to bypass security controls and execute arbitrary code on systems using JMS ObjectMessages, potentially compromising data, operations, and system integrity.
Technical details
The vulnerability is a deserialization of untrusted data flaw (CWE-502) in the IBM MQ JMS client that bypasses the Java deserialization allowlist. An authenticated, network-connected attacker can exploit this by sending a specially crafted JMS ObjectMessage to execute arbitrary code on systems consuming those messages. The attack requires prior authentication to MQ and does not require user interaction. IBM has released cumulative security updates for all affected versions (9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and 10.0.0.5).
Affected products
- IBM MQ 9.1.0.0 through 9.1.0.37 LTS; 9.2.0.0 through 9.2.0.43 LTS; 9.3.0.0 through 9.3.0.41 LTS; 9.3.0.0 through 9.3.5.1 CD; 9.4.0.0 through 9.4.0.25 LTS; 9.4.0.0 through 9.4.5.1 CD; 10.0.0.0
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Cumulative security updates released: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5