Arbitrary Code Execution Vulnerability in IBM MQ Products
CVE-2026-11729

8.5HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-11729?

The vulnerability in IBM MQ affects several instances of the product, allowing an authenticated attacker to exploit unsafe deserialization, leading to JNDI injection attacks. This can result in the execution of arbitrary code in client applications, posing significant risks to system integrity and security. Users are advised to apply available patches and updates to mitigate potential threats.

Affected Version(s)

MQ 9.1.0.0 <= 9.1.0.37 LTS

MQ 9.2.0.0 <= 9.2.0.43 LTS

MQ 9.3.0.0 <= 9.3.0.41 LTS

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.