Junglewise Threat Intelligence

CVE-2026-17179: IBM Db2 Mirror for i command injection denial of service

CVE-2026-17179 · Severity: high · CVSS 8.5 · Published 2026-08-14

Technologies: IBM Db2 Mirror For I. Vendors: IBM.

Executive brief

IBM Db2 Mirror for i is a database management system used to store and manage business-critical data on IBM i systems. This vulnerability allows an authenticated attacker to cause the database service to stop responding by injecting malicious commands, disrupting operations and customer access to stored data.

Technical details

IBM Db2 Mirror for i is vulnerable to OS command injection (CWE-78) due to improper neutralization of special elements in commands. The vulnerability requires valid authentication credentials to exploit but does not require any special user privileges or interaction from another party. An authenticated remote attacker can inject specially crafted commands to trigger a denial of service condition that affects the availability of the database service. Patches are expected to be available from IBM; organizations should check IBM support communications for fixed versions.

Affected products

  • IBM Db2 Mirror for i 7.4, 7.5, 7.6

Timeline

  • 2026-08-14: disclosed

References

Related threats