Improper Pathname Limitation in IBM Db2 Mirror for i Products
CVE-2026-17081

8.2HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 August 2026

What is CVE-2026-17081?

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 contain a vulnerability that allows a remote attacker to write arbitrary files. This is possible due to improper restrictions placed on the pathname, potentially enabling unauthorized access to restricted directories. Users are advised to review the vendor advisory for mitigation strategies and apply patches as necessary to secure their systems.

Affected Version(s)

Db2 Mirror for i 7.4

Db2 Mirror for i 7.5

Db2 Mirror for i 7.6

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.