CVE-2026-12351
moderateUnauthenticated RCE via JNDI Lookup in IBM MQ IVT Application
IBM MQ contains a critical remote code execution flaw (CVSS 9.8) caused by unsafe JNDI lookup processing, a Log4Shell-class injection issue (CWE-74), that is exploitable only when the IVT (Installation Verification Test) application is deployed on the queue manager. A remote, unauthenticated attacker who can reach the service supplies crafted input that triggers a JNDI lookup to an attacker-controlled directory service (e.g., LDAP/RMI), allowing arbitrary code to be loaded and executed in the context of the MQ server process, with full impact to confidentiality, integrity, and availability. All listed 9.3 LTS/CD, 9.4 LTS, and 10.0.0.0 streams are affected, though only deployments running the IVT application are exposed to this specific path. No public proof of concept exists and the CVE is not in the CISA KEV catalog, so no exploitation is known to date, but the trivially network-exploitable profile makes prompt patching important for any IVT-enabled system.
What to do: Upgrade to IBM MQ versions later than the affected ranges listed above (apply IBM's fix for this CVE in each 9.3/9.4/10.0 stream). Immediately check whether the IVT application is deployed on any queue manager and undeploy/remove it if it is not needed, since IVT is only an installation-verification tool. Additionally, restrict network access to MQ listeners and egress-filter outbound connections to untrusted LDAP/RMI/directory endpoints to blunt JNDI-lookup exploitation even before patching completes.
| IBM MQ | 9.3.0.0 through 9.3.0.41 LTS |
| IBM MQ | 9.3.0.0 through 9.3.5.1 CD |
| IBM MQ | 9.4.0.0 through 9.4.0.25 LTS |
| IBM MQ | 9.4.0.0 through 9.4.5.1 LTS |
| IBM MQ | 10.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.
- Weakness
- CWE-74
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.