Junglewise Threat Intelligence

CVE-2026-16879: IBM Db2 Mirror for i authorization bypass

CVE-2026-16879 · Severity: high · CVSS 8.8 · Published 2026-08-14

Technologies: IBM Db2 Mirror For I. Vendors: IBM.

Executive brief

IBM Db2 Mirror for i is a database management interface for IBM's i operating system. An authenticated attacker can bypass security restrictions due to improper authorization checks, potentially gaining unauthorized access to sensitive database functions and data. This vulnerability requires valid credentials but allows circumvention of access controls once inside the system.

Technical details

The vulnerability is an authorization bypass (CWE-285: Improper Authorization) in Db2 Mirror for i that allows an authenticated remote attacker to bypass security restrictions through improper validation of user-supplied input. The flaw is in how the application enforces access control; a legitimate user with credentials can craft requests that circumvent authorization checks intended to restrict certain operations. The attack requires valid authentication credentials and network access to the Db2 Mirror for i interface, but no special user interaction. An attacker can use this to access data or perform operations beyond their assigned privileges. Patches are available from IBM.

Affected products

  • IBM Db2 Mirror for i 7.4, 7.5, 7.6

Timeline

  • 2026-08-14: disclosed

References

Related threats