Description
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.
Published: 2026-08-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local privilege escalation flaw exists in the oninit setuid-root utility of IBM Informix Dynamic Server. The vulnerability arises from improper access control in the setuid component, allowing a user with local access to elevate privileges to root. With root access, an attacker can execute arbitrary code and compromise the entire system, representing a significant risk to confidentiality, integrity, and availability.

Affected Systems

The flaw affects IBM Informix Dynamic Server versions 14.10 and 15.0. IBM released fixes for 14.10.xC13W13 and 15.0.1.14. All other versions not listed in the CNA data are not confirmed to be vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. EPSS data is not available, so the likelihood of exploitation remains uncertain, and the vulnerability is not currently listed in CISA's KEV catalog. The attack vector is local and likely requires the attacker to run or influence the oninit utility, as the vulnerability is tied to a setuid-root binary. If an attacker can execute a malicious command or replace assets used by oninit, they can gain root privileges and deploy arbitrary code on the affected system.

Generated by OpenCVE AI on August 13, 2026 at 02:18 UTC.

Remediation

Vendor Solution

The issue has been fixed in IBM Informix versions 14.10.xC13W13 and 15.0.1.14.  * Fixes are available on  IBM Fix Central - Select Fixes - Informix Server https://www.ibm.com/support/fixcentral/swg/selectFixes .  * Follow the instructions for  Database server upgrades https://www.ibm.com/docs/en/informix-servers/14.10  in the Informix Servers documentation.


OpenCVE Recommended Actions

  • Apply the IBM Informix patch 14.10.xC13W13 or 15.0.1.14 from IBM Fix Central
  • Follow IBM's database server upgrade instructions to correctly install the fix
  • Verify that the oninit binary is owned by root and has proper setuid and permission settings, restricting its use to administrators only

Generated by OpenCVE AI on August 13, 2026 at 02:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical ubuntu Linux
Hp
Hp hp-ux
Ibm aix
Ibm linux On Ibm Z
Linux
Linux linux Kernel
Novell
Novell suse Linux
Oracle
Oracle solaris
Redhat
Redhat desktop
CPEs cpe:2.3:o:canonical:ubuntu_linux:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:desktop:-:*:*:*:*:*:*:*
Vendors & Products Canonical
Canonical ubuntu Linux
Hp
Hp hp-ux
Ibm aix
Ibm linux On Ibm Z
Linux
Linux linux Kernel
Novell
Novell suse Linux
Oracle
Oracle solaris
Redhat
Redhat desktop

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.
Title IBM Informix Dynamic Server Privilege Escalation Vulnerability in oninit Utility
First Time appeared Ibm
Ibm informix Dynamic Server
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:informix_dynamic_server:14.10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:informix_dynamic_server:14.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:informix_dynamic_server:15.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:informix_dynamic_server:15.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm informix Dynamic Server
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Canonical Ubuntu Linux
Hp Hp-ux
Ibm Aix Informix Dynamic Server Linux On Ibm Z
Linux Linux Kernel
Novell Suse Linux
Oracle Solaris
Redhat Desktop
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:26:34.887Z

Reserved: 2026-06-25T18:56:30.705Z

Link: CVE-2026-13367

cve-icon Vulnrichment

Updated: 2026-08-13T19:21:49.491Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T21:17:35.260

Modified: 2026-08-18T14:47:40.487

Link: CVE-2026-13367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:30:12Z

Weaknesses