Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
Published: 2026-08-14
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 contain an OS command injection flaw that allows a remote attacker to execute arbitrary CL commands. The flaw results from failure to neutralize special elements in a supplied command string, enabling full system compromise. The weakness is identified as CWE-78.

Affected Systems

The affected product is IBM Db2 Mirror for i for all releases 7.4, 7.5, and 7.6 on IBM i, including the sub‑versions 7.4.0, 7.4, 7.5.0, 7.5, 7.6.0, and 7.6.

Risk and Exploitability

The CVSS score of 9.9 classifies this as critical, and while the EPSS score is not reported, the absence of a CISA KEV listing does not diminish its potential risk. Remote attackers can exploit the vulnerability by sending a crafted command string to a network service that passes input to the CL interpreter, achieving arbitrary code execution on the host. The attack requires remote connectivity to the affected service and does not benefit from privileged local access prior to exploitation.

Generated by OpenCVE AI on August 14, 2026 at 20:22 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Apply the IBM PTF for your release: SJ10947 for 7.4, SJ10961 for 7.5, or SJ10948 for 7.6, obtained from IBM Fix Central.
  • Restrict network access to the Db2 Mirror for i instance so that only trusted hosts can communicate with services that accept CL commands.
  • Disable or secure any remote CL command interfaces, ensuring that input is validated or that such interfaces are turned off when not necessary.

Generated by OpenCVE AI on August 14, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:22:46.540Z

Reserved: 2026-07-24T18:44:52.306Z

Link: CVE-2026-17186

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:51.127

Modified: 2026-08-14T20:16:51.127

Link: CVE-2026-17186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T21:15:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')