CVE-2026-12354
moderateAuthenticated RCE via JNDI Injection in IBM MQ Resource Adapter IVT App
IBM MQ ships a Resource Adapter Installation Verification Test (IVT) application that improperly validates JNDI names (CWE-913), allowing an authenticated attacker with network access to supply a malicious JNDI lookup and achieve arbitrary code execution on the application server hosting the resource adapter, in a Log4Shell-style pattern. Exploitation requires valid credentials (PR:L) and somewhat difficult conditions (AC:H), but success yields high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.5). Every currently shipped release stream is affected, from 9.1 LTS through 9.2, 9.3, and 9.4 LTS/CD up to 10.0.0.0. No public proof of concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is presumed unlikely at this time.
What to do: Upgrade to the newest fix pack IBM has published for your release stream — anything beyond the affected ranges listed above — and prioritize migration off the aging 9.1/9.2 LTS streams, which are at or near end of support. If the Resource Adapter Installation Verification Test application is not required in production, undeploy or disable it, restrict authenticated access to it, and limit the application server's ability to make outbound JNDI/LDAP/RMI connections. Review application server logs for unexpected JNDI lookups or outbound directory traffic as an indicator of attempted exploitation.
| IBM MQ | 9.1.0.0 through 9.1.0.37 LTS |
| IBM MQ | 9.2.0.0 through 9.2.0.43 LTS |
| IBM MQ | 9.3.0.0 through 9.3.0.41 LTS |
| IBM MQ | 9.3.0.0 through 9.3.5.1 CD |
| IBM MQ | 9.4.0.0 through 9.4.0.25 LTS |
| IBM MQ | 9.4.0.0 through 9.4.5.1 CD |
| IBM MQ | 10.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.
- Weakness
- CWE-913
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.