CVE-2026-12354
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.45%
- CWE
- CWE-913
- Published
- 2026-09-15
- Last modified
- 2026-09-16
Affected products
- IBM MQ
- IBM MQ
- IBM MQ
- IBM MQ
- IBM MQ
Weakness type
Related vulnerabilities
- CVE-2025-68613 — n8n Vulnerable to Remote Code Execution via Expression Injection
- CVE-2022-36067 — vm2 vulnerable to Sandbox Escape before v3.9.11
- CVE-2023-29017 — vm2 Sandbox Escape vulnerability
- CVE-2023-50386 — Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
- CVE-2023-29199 — vm2 Sandbox escape vulnerability
- CVE-2026-23830 — SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor
- CVE-2026-22709 — vm2 has a Sandbox Escape
- CVE-2025-25270 — Remote Code Execution via Unauthenticated Configuration Manipulation