Privilege Escalation Vulnerability in IBM Db2 Database Software
CVE-2026-10543

8.2HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-10543?

The IBM Db2 database software versions 11.5.0 to 11.5.9 and 12.1.0 to 12.1.5 is exposed to a privilege escalation risk due to the handling of specially crafted queries. This vulnerability allows attackers to escalate their privileges, potentially gaining unauthorized access and control over sensitive data and functionalities within the database. Users are advised to apply the patches provided by IBM promptly to mitigate any potential security risks.

Affected Version(s)

Db2 11.5.0 <= 11.5.9

Db2 12.1.0 <= 12.1.5

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability was reported to IBM by Nicolas Verdier, Amazon.
.