Command Injection Vulnerability in IBM Db2 Mirror for i
CVE-2026-17179

8.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 August 2026

What is CVE-2026-17179?

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are susceptible to a command injection vulnerability that enables a remote authenticated attacker to execute arbitrary commands. This could potentially lead to a denial of service, disrupting the availability of the service. It is advised that organizations using these versions monitor their systems and apply appropriate patches provided by IBM to mitigate any risks associated with this vulnerability.

Affected Version(s)

Db2 Mirror for i 7.4

Db2 Mirror for i 7.5

Db2 Mirror for i 7.6

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.