Junglewise Threat Intelligence

CVE-2026-14501: IBM Db2 Genius Hub and Agentics use of dangerous functions

CVE-2026-14501 · Severity: medium · CVSS 4.3 · Published 2026-07-17

Vendors: IBM.

Executive brief

IBM Db2 Genius Hub and IBM Agentics are data management and automation tools. A security vulnerability has been identified where the software uses certain programming functions without proper safety restrictions. This could allow an authenticated attacker to potentially execute unauthorized code or access sensitive information, impacting the integrity and confidentiality of the system.

Technical details

IBM Db2 Genius Hub (1.1, 1.1.1, 1.1.2) and IBM Agentics (1.0) are affected by a vulnerability classified as the use of potentially dangerous functions (CWE-676). The root cause is the implementation of functions that lack sufficient restrictions, which can be abused by an attacker. An attacker with low-privileged network access can exploit this flaw to execute arbitrary code or obtain sensitive information. The vulnerability is tracked as CVE-2026-14501 and has a CVSS base score of 4.3. Users are advised to refer to IBM support documentation for remediation steps and potential patches.

Affected products

  • IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2
  • IBM Agentics 1.0

Timeline

  • 2026-07-17: disclosed: Initial advisory published by IBM and NVD

References