Threat intelligence dashboard
CVE-2026-12354high

IBM MQ Resource Adapter IVT message-driven bean is vulnerable to remote code execution via JNDI injection

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.

Risk score

7.5

CVSS 3.1

Vendor
IBM
Product
MQ
CWE
CWE-913
Published
Sep 15, 2026
Updated
Sep 16, 2026
CISA KEV
Not flagged

Affected products and versions

MQ

IBM

Version / rangeStatusType
9.1.0.0 to 9.1.0.37 LTSaffectedsemver
9.2.0.0 to 9.2.0.43 LTSaffectedsemver
9.3.0.0 to 9.3.0.41 LTSaffectedsemver
9.3.0.0 to 9.3.5.1 CDaffectedsemver
9.4.0.0 to 9.4.0.25 LTSaffectedsemver
9.4.0.0 to 9.4.5.1 CDaffectedsemver
10.0.0.0affected

Technical metrics

7.5

CVSS 3.1

Severity
high
Source
ibm
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H