CVE-2026-12351
IBM MQ JNDI injection allows unauthenticated remote code execution (CVE-2026-12351)
IBM MQ in the 9.3.0.0, 9.4.0.0 and 10.0.0.0 release lines is vulnerable to unauthenticated remote code execution via unsafe JNDI lookup when the IVT application is deployed. CVSS 9.8 critical. Apply IBM's fix; confirm the correct build for your release.
What happened
IBM MQ processes JNDI lookups unsafely when the IVT application is deployed. A remote attacker who can reach the MQ service can trigger this behaviour over the network and execute arbitrary code. No credentials are required, and no action is needed by a legitimate user. The CVSS score is 9.8 critical, reflecting high impact to confidentiality, integrity and availability.
The CVE record does not report active exploitation or public disclosure. It is not listed in CISA's Known Exploited Vulnerabilities catalogue.
Who is affected
IBM MQ versions 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 are affected. The vulnerable behaviour depends on the IVT application being deployed, so teams should confirm whether that application is present on any MQ installation before applying the fix.
What to do now
- Apply IBM's fix. IBM has made a fix available; fixed build numbers are not listed in the CVE data shown here, so check the IBM support page for this CVE to confirm the correct build for your 9.3.0.0, 9.4.0.0 or 10.0.0.0 release before applying it.
- Verify whether the IVT application is deployed in your MQ environments, because the unsafe JNDI lookup is triggered when it is present.
- Until patching is complete, restrict network access to the MQ service so only trusted hosts can reach it. IBM has not published a workaround in this advisory.
- Monitor MQ hosts for unexpected processes or connections after any suspected exposure.
How to detect it
IBM has not published indicators of compromise for this CVE. The exposure conditions to verify are whether the IVT application is deployed on MQ installations and whether the MQ service is reachable from untrusted networks.
Beyond the patch
Unauthenticated remote code execution in IBM MQ changes the trust model for every application that depends on it. Treat this as an exposure problem first: know where the MQ service and IVT application are reachable before an incident. Virtual CISO Services (vCISO) can help run that exposure review; if code execution does occur, Managed Detection & Response (MDR) can detect the endpoint and SIEM trail.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| MQ | 9.3.0.0 – ≤ 9.3.0.41 LTS 9.3.0.0 – ≤ 9.3.5.1 CD 9.4.0.0 – ≤ 9.4.0.25 LTS 9.4.0.0 – ≤ 9.4.5.1 LTS 10.0.0.0 | No fixed version listed yet |