Code Execution Vulnerability in IBM MQ by IBM
CVE-2026-12354
7.5HIGH
What is CVE-2026-12354?
An improper validation of Java Naming and Directory Interface (JNDI) names within the Resource Adapter Installation Verification Test application in IBM MQ allows authenticated attackers to execute arbitrary code. This security flaw affects several versions of the software, making them susceptible to exploitation if not addressed promptly.
Affected Version(s)
MQ 9.1.0.0 <= 9.1.0.37 LTS
MQ 9.2.0.0 <= 9.2.0.43 LTS
MQ 9.3.0.0 <= 9.3.0.41 LTS