Deserialization Filter Bypass in IBM MQ Client Libraries
CVE-2026-10751

7.5HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-10751?

IBM MQ Java and JMS client libraries are susceptible to a deserialization filter bypass that can potentially allow authenticated attackers to execute arbitrary code on client applications. This vulnerability arises during exception handling, which may leave client applications exposed to manipulation if protective measures are not in place. Recommended actions include applying necessary patches and updating to protected versions as specified in vendor advisories.

Affected Version(s)

MQ 9.1.0.0 <= 9.1.0.37 LTS

MQ 9.2.0.0 <= 9.2.0.43 LTS

MQ 9.3.0.0 <= 9.3.0.41 LTS

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.