IBMCVE-2026-11729
IBM MQ: code execution
High8.5CVE-2026-11729 · Published Sep 15, 2026 · updated Sep 16, 2026
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| MQ Product | >= 9.1.0.0, <= 9.1.0.37 LTS | No fix yet |
| >= 9.2.0.0, <= 9.2.0.43 LTS | No fix yet | |
| >= 9.3.0.0, <= 9.3.0.41 LTS | No fix yet | |
| >= 9.3.0.0, <= 9.3.5.1 CD | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-502
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | IBM Cloud Pak for Business Automation: cross-site scripting | Medium5.4 | No fix yet |
| Sep 15 | IBM Business Automation Workflow containers and traditional: XML external entity | High7.1 | No fix yet |
| Sep 15 | IBM Security Verify Access: denial of service | High7.5 | No fix yet |
| Sep 15 | IBM MQ: information disclosure | High8.1 | No fix yet |
| Sep 15 | IBM MQ: denial of service | High7.1 | No fix yet |
| Sep 15 | IBM MQ: code execution | High8.8 | No fix yet |