CVE-2026-11729
moderateAuthenticated RCE via JNDI injection in IBM MQ client applications
IBM MQ contains an unsafe deserialization flaw (CWE-502) in versions spanning the 9.1 LTS through 10.0.0.0 release streams that enables JNDI injection attacks. A remote, authenticated attacker with low privileges can trigger the flaw by supplying malicious data that the client deserializes and resolves through JNDI, resulting in arbitrary code execution in client applications. Successful exploitation compromises confidentiality, integrity, and availability across a scope change, reflected in the high CVSS 3.1 score of 8.5. The attack requires valid credentials and high attack complexity, so it is most realistic inside multi-tenant environments or where attacker-controlled accounts exist. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the fix pack IBM identifies in its advisory for each affected LTS and CD stream, prioritizing any system where untrusted or multi-tenant users hold authenticated MQ client access. As interim hardening, restrict outbound LDAP/RMI connectivity from JVMs running MQ client applications to block malicious JNDI lookup resolution, and monitor for anomalous outbound directory-service connections. Audit which accounts can authenticate and connect with client privileges, since exploitation requires valid credentials.
| IBM MQ | 9.1.0.0 through 9.1.0.37 LTS |
| IBM MQ | 9.2.0.0 through 9.2.0.43 LTS |
| IBM MQ | 9.3.0.0 through 9.3.0.41 LTS |
| IBM MQ | 9.3.0.0 through 9.3.5.1 CD |
| IBM MQ | 9.4.0.0 through 9.4.0.25 LTS |
| IBM MQ | 9.4.0.0 through 9.4.5.1 CD |
| IBM MQ | 10.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.