ZeroHour

CVE-2026-11729

moderate

Authenticated RCE via JNDI injection in IBM MQ client applications

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

IBM MQ contains an unsafe deserialization flaw (CWE-502) in versions spanning the 9.1 LTS through 10.0.0.0 release streams that enables JNDI injection attacks. A remote, authenticated attacker with low privileges can trigger the flaw by supplying malicious data that the client deserializes and resolves through JNDI, resulting in arbitrary code execution in client applications. Successful exploitation compromises confidentiality, integrity, and availability across a scope change, reflected in the high CVSS 3.1 score of 8.5. The attack requires valid credentials and high attack complexity, so it is most realistic inside multi-tenant environments or where attacker-controlled accounts exist. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the fix pack IBM identifies in its advisory for each affected LTS and CD stream, prioritizing any system where untrusted or multi-tenant users hold authenticated MQ client access. As interim hardening, restrict outbound LDAP/RMI connectivity from JVMs running MQ client applications to block malicious JNDI lookup resolution, and monitor for anomalous outbound directory-service connections. Audit which accounts can authenticate and connect with client privileges, since exploitation requires valid credentials.

Affected
IBM MQ9.1.0.0 through 9.1.0.37 LTS
IBM MQ9.2.0.0 through 9.2.0.43 LTS
IBM MQ9.3.0.0 through 9.3.0.41 LTS
IBM MQ9.3.0.0 through 9.3.5.1 CD
IBM MQ9.4.0.0 through 9.4.0.25 LTS
IBM MQ9.4.0.0 through 9.4.5.1 CD
IBM MQ10.0.0.0
Estimated exposure
moderate≈ tens of thousands of enterprise deployments worldwide (order of magnitude; thousands of internet-exposed queue managers) — IBM MQ is a market-leading enterprise messaging middleware deployed mainly inside large corporate networks (public scans such as Shodan typically show only low thousands of internet-exposed queue managers), while the client-side nature of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.

Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.