Executive brief
IBM Db2 Mirror for i is a database management tool for IBM Power Systems running i operating system. CVE-2026-16915 is a path traversal vulnerability that allows authenticated attackers to read sensitive information from the system by bypassing directory restrictions through improper input validation in the GUI.
Technical details
This vulnerability is a path traversal flaw (CWE-22) in IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. An authenticated remote attacker can exploit improper input validation to traverse directory structures and access sensitive files outside intended directories. The attack requires prior authentication but no user interaction, and operates over the network. The vulnerability allows confidentiality breaches through unauthorized file read access. IBM has published security patches addressing this and multiple related vulnerabilities in the Db2 Mirror for i GUI.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, 7.6
Timeline
- 2026-08-14: disclosed
- other: CVE-2026-16915 assigned