Executive brief
IBM Db2 Mirror for i is a database management system for IBM i servers that handles sensitive business data and operations. An authenticated attacker can exploit improper authentication enforcement to access sensitive information without proper authorization. This could lead to unauthorized disclosure of confidential business data stored in the database.
Technical details
CVE-2026-17175 is an improper authentication vulnerability (CWE-287) in IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. The vulnerability exists due to improper authentication enforcement in the application. An authenticated remote attacker can exploit this flaw via network access to obtain sensitive information. The vulnerability requires authentication but allows an attacker to bypass authorization controls to access data they should not be permitted to view. IBM has published a security bulletin with this and other related vulnerabilities affecting the Db2 Mirror for i GUI.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, 7.6
Timeline
- 2026-08-14: disclosed