CVE-2026-12354

Summary

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.

Affected Software

VendorProductVersion RangeStatus
IBMMQ9.1.0.0 <= 9.1.0.37 LTSaffected
IBMMQ9.2.0.0 <= 9.2.0.43 LTSaffected
IBMMQ9.3.0.0 <= 9.3.0.41 LTSaffected
IBMMQ9.3.0.0 <= 9.3.5.1 CDaffected
IBMMQ9.4.0.0 <= 9.4.0.25 LTSaffected
IBMMQ9.4.0.0 <= 9.4.5.1 CDaffected
IBMMQ10.0.0.0affected

Weaknesses

  • CWE-913: CWE-913 Improper Control of Dynamically-Managed Code Resources

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References