Executive brief
IBM Db2 Mirror for i is a database management system used by organizations to manage and protect critical data. CVE-2026-16708 allows a remote attacker to obtain sensitive information by controlling system configuration settings externally. This could lead to exposure of confidential business data and compromise of database integrity without requiring authentication.
Technical details
CVE-2026-16708 is an information disclosure vulnerability in IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 resulting from improper controls on external system configuration modification. The vulnerability allows a remote, unauthenticated attacker to access sensitive information by manipulating system configuration parameters. Attack vector is network-based with no authentication or user interaction required. An attacker can exploit this to read sensitive database configuration, credentials, or operational data. IBM has published security updates addressing this and multiple related vulnerabilities in the Db2 Mirror for i GUI.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, 7.6
Timeline
- 2026-08-14: disclosed