Junglewise Threat Intelligence

CVE-2026-10109: IBM Db2 remote code execution in DRDA handshake

CVE-2026-10109 · Severity: critical · CVSS 9.8 · Published 2026-06-30

Executive brief

IBM Db2, a widely used enterprise database management system, is affected by a critical security flaw in its communication protocol. An unauthorized attacker can exploit this vulnerability to execute malicious commands on the database server without needing a username or password. This could lead to a total compromise of the database, including the theft of sensitive customer data, service disruption, or the installation of ransomware.

Technical details

IBM Db2 contains a code injection vulnerability (CWE-94) within its implementation of the Distributed Relational Database Architecture (DRDA) protocol. The flaw exists in the pre-authentication handshake process, where improper validation of initial connection requests allows for remote code execution. An unauthenticated attacker can trigger this vulnerability over the network by sending a specially crafted DRDA handshake packet. Successful exploitation grants the attacker the ability to execute arbitrary code with the privileges of the Db2 instance owner. IBM has released special builds for versions 11.5.9 and 12.1.4 to remediate this issue.

Affected products

  • IBM Db2 11.5.0 - 11.5.9, 12.1.0 - 12.1.4

Timeline

  • 2026-06-23: disclosed: Initial publication by IBM
  • 2026-06-23: patched: Special builds released for V11.5 and V12.1
  • 2026-06-30: advisory: NVD publication date

References

Related threats