JNDI Injection Vulnerability in IBM MQ Products
CVE-2026-12355
8.1HIGH
What is CVE-2026-12355?
A vulnerability in IBM MQ allows potential attackers to exploit JNDI injection due to improper input validation. This flaw can lead to unauthorized information disclosure and may enable remote code execution, posing a significant risk to data security. Users of affected IBM MQ versions should promptly apply available patches to mitigate the threat.
Affected Version(s)
MQ 9.1.0.0 <= 9.1.0.37 LTS
MQ 9.2.0.0 <= 9.2.0.43 LTS
MQ 9.3.0.0 <= 9.3.0.41 LTS