ZeroHour

CVE-2026-13293

moderate

Authenticated Remote Code Execution via Deserialization in IBM MQ

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM MQ contains a flaw in which untrusted data is deserialized (CWE-502), allowing a remote authenticated attacker to execute arbitrary code on the system running the queue manager. The flaw is triggered over the network by an attacker holding valid MQ credentials or a compromised application account who submits crafted serialized data that the broker processes, achieving code execution with the privileges of the MQ process. The issue is rated high severity (CVSS 3.1: 8.8) with high impact on confidentiality, integrity, and availability, meaning a successful attacker effectively controls the messaging server and the message traffic it handles. The affected footprint is broad across the supported product line: IBM MQ 9.1 LTS through 9.4 LTS/CD streams and 10.0.0.0. There is no known public proof of concept, the CVE is not on the CISA KEV list, and no exploitation in the wild has been reported, though the authentication requirement makes credential hygiene a critical compensating control.

What to do: Apply IBM's fix packs and move to builds later than the affected terminal levels (9.1.0.37, 9.2.0.43, 9.3.0.41 / 9.3.5.1, 9.4.0.25 / 9.4.5.1) or off 10.0.0.0 per IBM's security bulletin. Tighten channel authentication with CHLAUTH rules, TLS, and least-privilege MQ user accounts so a single stolen credential cannot reach privileged channels. Review MQ error and authentication logs for unexpected client connections or activity from low-privilege accounts.

Affected
IBM MQ9.1.0.0 - 9.1.0.37 LTS
IBM MQ9.2.0.0 - 9.2.0.43 LTS
IBM MQ9.3.0.0 - 9.3.0.41 LTS
IBM MQ9.3.0.0 - 9.3.5.1 CD
IBM MQ9.4.0.0 - 9.4.0.25 LTS
IBM MQ9.4.0.0 - 9.4.5.1 CD
IBM MQ10.0.0.0
Estimated exposure
moderate≈ tens of thousands of enterprise installations globally; likely only low thousands of internet-exposed systems (clearly an estimate) — IBM MQ is enterprise messaging middleware deployed by thousands of large organizations (finance, government, retail), but public internet scans typically show only low thousands of exposed MQ listeners or web consoles since most queue…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

IBM security advisory (AV26-922)

Canadian Cyber Centre relays IBM advisory for Langflow, MQ, and Sterling File Gateway flaws including MQ remote code execution (CVE-2026-13293).

Canadian Cyber Centre advisory AV26-922 relays IBM fixes for Langflow OSS (versions through 1.11.5 across release lines), IBM MQ (10.0.0.0 and 9.x LTS/CD through 9.4.5.1), and Sterling File Gateway (through 6.2.2.1). CVE-2026-13293 is a remote code execution flaw in IBM MQ Java messaging caused by an incomplete security scanner blocklist enabling network-based code execution. CVE-2026-19290 is an improper access control vulnerability in IBM Sterling File Gateway. Administrators are urged to review and apply the necessary updates.