Junglewise Threat Intelligence

CVE-2026-11906: IBM Db2 denial of service in XMLTable query logic

CVE-2026-11906 · Severity: medium · CVSS 6.5 · Published 2026-06-30

Executive brief

IBM Db2 is a database management system used by enterprises to store and manage critical business data. A vulnerability in how the system processes specific database queries could allow a registered user to crash the database server. This would result in a service outage, preventing applications and employees from accessing necessary data until the system is recovered.

Technical details

IBM Db2 (including Db2 Connect Server) is vulnerable to a denial of service (DoS) attack. The flaw is rooted in CWE-1284 (Improper Validation of Specified Quantity in Input) within the data query logic of XMLTable-derived columns. An authenticated attacker with network access can exploit this by submitting specially crafted queries that fail to be properly neutralized, leading to a system crash or hang. The vulnerability affects versions 11.5 and 12.1 across Linux, UNIX, and Windows platforms. IBM has released special builds (interim fixes) for versions 11.5.9 and 12.1.4 to remediate the issue.

Affected products

  • IBM Db2 for Linux, UNIX and Windows 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
  • IBM Db2 Connect Server 11.5.0 - 11.5.9, 12.1.0 - 12.1.4

Timeline

  • 2026-06-23: disclosed: Initial publication by IBM
  • 2026-06-30: advisory: NVD publication date

References

Related threats