Buffer Overflow Vulnerability in IBM Db2 Database Products
CVE-2026-10535

8.4HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-10535?

The vulnerability in IBM Db2 affects versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4, specifically within the setgid helper db2flacc. This flaw can potentially allow unauthorized access or manipulation of data, making it crucial for users to apply available patches and stay updated to prevent exploitation of this security weakness.

Affected Version(s)

Db2 11.5.0 <= 11.5.9

Db2 12.1.0 <= 12.1.4

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.