Description
IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions.
Published: 2026-07-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in IBM Db2 Genius Hub 1.1 through 1.1.2 and IBM Agentics 1.0 and results from the use of a function that is considered potentially dangerous without adequate safeguards. This leads to the possibility of arbitrary code execution or the exposure of sensitive information, as the function could be invoked with malicious input. The weakness is classified as CWE‑676, indicating improper use of a function that may carry unintended side effects.

Affected Systems

Systems affected include IBM Agentics version 1.0 and IBM Db2 Genius Hub versions 1.1, 1.1.1, and 1.1.2. These products are delivered via IBM’s business analytics suites and are typically installed on enterprise servers handling potentially sensitive data. Any environment deploying these specific releases is subject to the vulnerability until a fix is applied.

Risk and Exploitability

With a CVSS score of 4.3, the vulnerability presents a moderate risk level. The EPSS score of less than 1% suggests very low exploitation probability at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be application‑level or local, because the description does not specify remote network exploitation but indicates that the dangerous function can be triggered with suitable input. An attacker with sufficient access to influence the function’s parameters could potentially execute code or read protected data.

Generated by OpenCVE AI on July 30, 2026 at 23:34 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now.ProductVersion impactedRemediationIBM Db2 Genius Hub &amp; Agentics1.1, 1.1.1, 1.1.2Upgrade to: IBM Db2 Genius Hub 1.1.3https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EOther%20software&amp;product=ibm/Information+Management/IBM+Db2+Genius+Hub&amp;release=1.1.3.0&amp;platform=All&amp;function=all


OpenCVE Recommended Actions

  • Apply the IBM‑recommended update to IBM Db2 Genius Hub 1.1.3 via IBM Fix Central.
  • If an immediate upgrade is not possible, review application configuration to disable or restrict the use of the dangerous function, following IBM’s guidance for safe usage.
  • Monitor application logs for unexpected function invocations and isolate affected services from untrusted inputs until the patch is deployed.

Generated by OpenCVE AI on July 30, 2026 at 23:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions.
Title Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub
First Time appeared Ibm
Ibm agentics
Ibm db2 Genius Hub
Weaknesses CWE-676
CPEs cpe:2.3:a:ibm:agentics:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:agentics:1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_genius_hub:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_genius_hub:1.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm agentics
Ibm db2 Genius Hub
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Ibm Agentics Db2 Genius Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-20T18:02:26.778Z

Reserved: 2026-07-02T18:00:48.051Z

Link: CVE-2026-14501

cve-icon Vulnrichment

Updated: 2026-07-20T18:00:32.014Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:45:05Z

Weaknesses
  • CWE-676

    Use of Potentially Dangerous Function