CVE-2026-12355
moderateUnauthenticated JNDI Injection in IBM MQ Could Lead to RCE
IBM MQ contains a JNDI (Java Naming and Directory Interface) injection flaw caused by insufficient input validation of attacker-controlled data, identified as CVE-2026-12355 with a high CVSS 3.1 base score of 8.1. An unauthenticated remote attacker who can reach an affected queue manager may supply crafted input that triggers a JNDI lookup against an attacker-controlled naming/directory service (such as LDAP or RMI), which can result in information disclosure or remote code execution on the MQ server. The issue spans an unusually broad set of supported releases, from 9.1 LTS through the 9.3/9.4 continuous delivery streams and initial 10.0.0.0 code, so most currently deployed MQ estates are likely in scope. Exploitation requires high attack complexity per the CVSS vector, which somewhat lowers practical exploitability. There is no known public proof of concept, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported to date.
What to do: Apply IBM's fixed fix packs for your release stream as soon as they are available (the affected ranges indicate fixes land in the next fix pack of each 9.1/9.2/9.3/9.4 stream and a subsequent 10.0 build; confirm exact fixed levels in IBM's advisory). Until patched, restrict network access to MQ listeners and admin channels so only trusted clients can connect, and enforce egress filtering on MQ servers to block outbound LDAP/RMI connections to untrusted destinations, which blunts JNDI lookup callbacks. Also review queue manager and connection logs for unexpected JNDI lookups or outbound directory traffic, and prioritize any queue manager reachable from the internet.
| IBM MQ | 9.1.0.0 through 9.1.0.37 LTS |
| IBM MQ | 9.2.0.0 through 9.2.0.43 LTS |
| IBM MQ | 9.3.0.0 through 9.3.0.41 LTS |
| IBM MQ | 9.3.0.0 through 9.3.5.1 CD |
| IBM MQ | 9.4.0.0 through 9.4.0.25 LTS |
| IBM MQ | 9.4.0.0 through 9.4.5.1 CD |
| IBM MQ | 10.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI injection attacks due to insufficient input validation, potentially leading to information disclosure or remote code execution.
- Weakness
- CWE-74
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.