SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12354

HIGH · CVSS 7.5 EPSS 0.45%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM MQ versions 9.1.0 through 10.0.0 are vulnerable to arbitrary code execution due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application, allowing authenticated attackers to exploit this flaw. The potential impact includes unauthorized access and control over the application server, which could lead to data breaches or service disruptions. Organizations using these versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-12354
Severity
HIGH
CVSS
7.5
EPSS
0.45%

Original NVD Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.