Denial of Service Vulnerability in IBM MQ by Improper TLS Certificate Validation
CVE-2026-12150

7HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-12150?

A vulnerability in IBM MQ allows remote attackers, possessing a trusted TLS client certificate, to execute a denial of service attack. This is due to the improper handling of nested certificate data during the TLS certificate processing phase. If exploited, this vulnerability could lead to disruptions in service and potentially expose sensitive memory contents.

Affected Version(s)

MQ 9.1.0.0 <= 9.1.0.37 LTS

MQ 9.2.0.0 <= 9.2.0.43 LTS

MQ 9.3.0.0 <= 9.3.0.41 LTS

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.