Junglewise Threat Intelligence

CVE-2026-17081: IBM Db2 Mirror for i path traversal arbitrary file write

CVE-2026-17081 · Severity: high · CVSS 8.2 · Published 2026-08-14

Technologies: IBM Db2 Mirror For I. Vendors: IBM.

Executive brief

IBM Db2 Mirror for i is a database mirroring solution used by organizations to replicate and manage database instances. A path traversal vulnerability allows a remote attacker to write arbitrary files to any location on the system without authentication, potentially leading to code execution, system compromise, or data integrity violations.

Technical details

This vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), where the application fails to properly validate and restrict file write operations to intended directories. The flaw is remotely exploitable over the network with no authentication or user interaction required. An attacker can manipulate pathname inputs to traverse directory boundaries and write malicious files to arbitrary locations on the system, potentially leading to remote code execution or system compromise. IBM has acknowledged the issue in versions 7.4, 7.5, and 7.6 of Db2 Mirror for i.

Affected products

  • IBM Db2 Mirror for i 7.4, 7.5, 7.6

Timeline

  • 2026-08-14: disclosed

References

Related threats