Executive brief
IBM Db2 Mirror for i is a database mirroring and high-availability solution for the IBM i platform. A flaw in its authentication mechanism allows a remote authenticated user to access sensitive information they should not be permitted to view. This could enable attackers to steal confidential business data or system configuration details without proper authorization.
Technical details
CVE-2026-16905 is an improper authentication vulnerability (CWE-287) in IBM Db2 Mirror for i that allows remote authenticated attackers to obtain sensitive information. The vulnerability stems from inadequate authentication validation, which fails to properly restrict access to protected resources. No user interaction is required; an authenticated attacker can exploit this over the network to read data they are not authorized to access. Patching is available through IBM; affected versions are 7.4, 7.5, and 7.6.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, and 7.6
Timeline
- 2026-08-14: disclosed
- other: Part of a multi-vulnerability security bulletin affecting Db2 Mirror for i GUI