Skip to content

CVE-2026-12351

IBM MQ JNDI injection allows unauthenticated remote code execution (CVE-2026-12351)

Critical 9.8 Vendor: IBM Published

IBM MQ in the 9.3.0.0, 9.4.0.0 and 10.0.0.0 release lines is vulnerable to unauthenticated remote code execution via unsafe JNDI lookup when the IVT application is deployed. CVSS 9.8 critical. Apply IBM's fix; confirm the correct build for your release.

What happened

IBM MQ processes JNDI lookups unsafely when the IVT application is deployed. A remote attacker who can reach the MQ service can trigger this behaviour over the network and execute arbitrary code. No credentials are required, and no action is needed by a legitimate user. The CVSS score is 9.8 critical, reflecting high impact to confidentiality, integrity and availability.

The CVE record does not report active exploitation or public disclosure. It is not listed in CISA's Known Exploited Vulnerabilities catalogue.

Who is affected

IBM MQ versions 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 are affected. The vulnerable behaviour depends on the IVT application being deployed, so teams should confirm whether that application is present on any MQ installation before applying the fix.

What to do now

  1. Apply IBM's fix. IBM has made a fix available; fixed build numbers are not listed in the CVE data shown here, so check the IBM support page for this CVE to confirm the correct build for your 9.3.0.0, 9.4.0.0 or 10.0.0.0 release before applying it.
  2. Verify whether the IVT application is deployed in your MQ environments, because the unsafe JNDI lookup is triggered when it is present.
  3. Until patching is complete, restrict network access to the MQ service so only trusted hosts can reach it. IBM has not published a workaround in this advisory.
  4. Monitor MQ hosts for unexpected processes or connections after any suspected exposure.

How to detect it

IBM has not published indicators of compromise for this CVE. The exposure conditions to verify are whether the IVT application is deployed on MQ installations and whether the MQ service is reachable from untrusted networks.

Beyond the patch

Unauthenticated remote code execution in IBM MQ changes the trust model for every application that depends on it. Treat this as an exposure problem first: know where the MQ service and IVT application are reachable before an incident. Virtual CISO Services (vCISO) can help run that exposure review; if code execution does occur, Managed Detection & Response (MDR) can detect the endpoint and SIEM trail.

Affected and fixed versions

ProductAffectedFixed in
MQ9.3.0.0 – ≤ 9.3.0.41 LTS
9.3.0.0 – ≤ 9.3.5.1 CD
9.4.0.0 – ≤ 9.4.0.25 LTS
9.4.0.0 – ≤ 9.4.5.1 LTS
10.0.0.0
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.