CVE-2026-17186

9.9

IBM · Db2 Mirror for i

IBM Db2 Mirror for i is vulnerable to remote command injection, allowing unauthenticated attackers to execute arbitrary CL commands via improper neutralization of special elements.

Executive summary

A critical remote command injection vulnerability in IBM Db2 Mirror for i allows unauthenticated attackers to execute arbitrary system commands, posing a severe risk of full system compromise.

Vulnerability

The software suffers from an OS Command Injection (CWE-78) vulnerability. The attack vector is network based, requires no authentication, and involves no user interaction.

Business impact

The ability for a remote, unauthenticated attacker to execute arbitrary commands on a database system represents a critical security failure. Successful exploitation could lead to total loss of confidentiality, integrity, and availability of database assets, potentially facilitating lateral movement within the network. The CVSS score of 9.9 reflects the extreme severity and ease of exploitation.

Remediation

Immediate Action: Apply the relevant Program Temporary Fix (PTF) immediately: SJ10947 for version 7.4, SJ10961 for version 7.5, or SJ10948 for version 7.6.

Proactive Monitoring: Audit system logs for unexpected CL command execution or unusual process spawning originating from the Db2 Mirror interface.

Compensating Controls: Restrict network access to the affected service via firewall rules to allow traffic only from trusted management segments.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this vulnerability and the ease of exploitation over the network, organizations must prioritize the application of the vendor provided PTFs. Delaying remediation significantly increases the window of exposure for critical database infrastructure.

More IBM CVEs