Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Published: 2026-08-12
Score: 9.8 Critical
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in IBM Db2 Mirror for i arises from a lack of proper neutralization of special characters within an OS command, allowing an attacker who can send specially crafted input to the service to execute arbitrary commands on the host system. This provides a pathway for full remote code execution, jeopardizing confidentiality, integrity, and availability of the affected database and the underlying operating system. The weakness is classified as CWE‑78, attributable to insecure command construction.

Affected Systems

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are affected. The specific patches that address this issue are PTF SJ10957 (IBM i Release 7.4), SJ10954 (IBM i Release 7.5), and SJ10951 (IBM i Release 7.6), available through IBM’s support links.

Risk and Exploitability

With a CVSS score of 9.8 the vulnerability is considered critical. An exploitation is possible by a remote attacker who can interact with the vulnerable component; the attack likely involves sending a crafted request that causes the vulnerable process to invoke an OS command containing unsanitized user input. The EPSS score is 1%, indicating a low but nonzero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog at this time. Nonetheless the high severity and remote nature mean the risk remains significant until the relevant patches are applied.

Generated by OpenCVE AI on August 13, 2026 at 14:52 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-SS1 PTF Numbers PTF Download Link 7.4 SJ10957 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10957 7.5 SJ10954 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10954 7.6 SJ10951 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10951 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Download the IBM PTF SJ10957 from the IBM support site and apply it to the IBM i Release 7.4 installation.
  • Download the IBM PTF SJ10954 from the IBM support site and apply it to the IBM i Release 7.5 installation.
  • Download the IBM PTF SJ10951 from the IBM support site and apply it to the IBM i Release 7.6 installation.

Generated by OpenCVE AI on August 13, 2026 at 14:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:*:*:*:*:*:*:*:*

Thu, 13 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Title IBM Db2 Mirror for i is vulnerable to OS command injection []
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-12T19:18:18.312Z

Reserved: 2026-07-24T08:09:18.503Z

Link: CVE-2026-16956

cve-icon Vulnrichment

Updated: 2026-08-12T17:58:04.865Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T18:17:25.133

Modified: 2026-08-13T16:47:02.353

Link: CVE-2026-16956

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T15:00:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')