ZeroHour

CVE-2026-12351

moderate

Unauthenticated RCE via JNDI Lookup in IBM MQ IVT Application

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

IBM MQ contains a critical remote code execution flaw (CVSS 9.8) caused by unsafe JNDI lookup processing, a Log4Shell-class injection issue (CWE-74), that is exploitable only when the IVT (Installation Verification Test) application is deployed on the queue manager. A remote, unauthenticated attacker who can reach the service supplies crafted input that triggers a JNDI lookup to an attacker-controlled directory service (e.g., LDAP/RMI), allowing arbitrary code to be loaded and executed in the context of the MQ server process, with full impact to confidentiality, integrity, and availability. All listed 9.3 LTS/CD, 9.4 LTS, and 10.0.0.0 streams are affected, though only deployments running the IVT application are exposed to this specific path. No public proof of concept exists and the CVE is not in the CISA KEV catalog, so no exploitation is known to date, but the trivially network-exploitable profile makes prompt patching important for any IVT-enabled system.

What to do: Upgrade to IBM MQ versions later than the affected ranges listed above (apply IBM's fix for this CVE in each 9.3/9.4/10.0 stream). Immediately check whether the IVT application is deployed on any queue manager and undeploy/remove it if it is not needed, since IVT is only an installation-verification tool. Additionally, restrict network access to MQ listeners and egress-filter outbound connections to untrusted LDAP/RMI/directory endpoints to blunt JNDI-lookup exploitation even before patching completes.

Affected
IBM MQ9.3.0.0 through 9.3.0.41 LTS
IBM MQ9.3.0.0 through 9.3.5.1 CD
IBM MQ9.4.0.0 through 9.4.0.25 LTS
IBM MQ9.4.0.0 through 9.4.5.1 LTS
IBM MQ10.0.0.0
Estimated exposure
moderatelikely thousands to low tens of thousands of installations, with only a subset (those with IVT deployed) actually exposed — IBM MQ is enterprise messaging middleware deployed at thousands of organizations worldwide (heavily concentrated in banking), with public internet scans historically showing on the order of ~10,000 reachable MQ listeners, and the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.

Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.