Junglewise Threat Intelligence

CVE-2026-16702: IBM Db2 null pointer dereference in federated server

CVE-2026-16702 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: IBM Db2, IBM DB2 Connect Server. Vendors: IBM.

Executive brief

IBM Db2 is a relational database system used by enterprises to store and manage critical business data. An authenticated attacker can trigger a crash in the Db2 federated server component, causing the database service to become unavailable and disrupting business operations that depend on database access.

Technical details

The vulnerability is a null pointer dereference (CWE-476) in IBM Db2 11.5.0–11.5.9 and 12.1.0–12.1.5 for Linux, UNIX, and Windows, including Db2 Connect Server. An attacker with valid database authentication credentials can trigger this defect through remote network access, causing the Db2 federated server process to crash and resulting in denial of service. No user interaction is required beyond the attacker supplying crafted database commands or queries. IBM has released security updates for affected versions (V11.5.9, V12.1.4, and V12.1.5) available at their support portal.

Affected products

  • IBM Db2 11.5.0 through 11.5.9, 12.1.0 through 12.1.5
  • IBM Db2 Connect Server 11.5.0 through 11.5.9, 12.1.0 through 12.1.5

Timeline

  • 2026-09-10: disclosed: Initial publication of security bulletin

References

Related threats