Denial of Service Vulnerability in IBM Db2 Database Solutions
CVE-2026-87958

8.1HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-87958?

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 are susceptible to a denial of service attack. This vulnerability allows a privileged user to potentially disable specific functionalities on the Db2 server under certain conditions, leading to service interruptions and impacting database availability. It is crucial for users of these versions to apply recommended patches and implement security best practices to safeguard their databases.

Affected Version(s)

Db2 11.5.0 <= 11.5.9

Db2 12.1.0 <= 12.1.5

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability was discovered by Dan Gardner, Amazon.
.