Junglewise Threat Intelligence

CVE-2026-17181: IBM Db2 Mirror for i path traversal in file write

CVE-2026-17181 · Severity: critical · CVSS 9.3 · Published 2026-08-14

Technologies: IBM Db2 Mirror For I. Vendors: IBM.

Executive brief

IBM Db2 Mirror for i is a database management system with a web-based GUI interface used to administer IBM i systems. A path traversal vulnerability in the file write functionality allows unauthenticated remote attackers to write files to arbitrary locations on the server, potentially enabling code execution, configuration tampering, or denial of service.

Technical details

CVE-2026-17181 is a path traversal vulnerability (CWE-22) in the IBM Db2 Mirror for i GUI that fails to properly validate and restrict file paths during write operations. The vulnerability is exploitable remotely without authentication (AV:N, PR:N) and requires no user interaction, allowing an attacker to construct malicious path parameters with directory traversal sequences (e.g., "../../../") to write files outside the intended restricted directory. A successful exploit could allow the attacker to overwrite critical files, inject malicious code, or degrade system availability. Patches addressing this vulnerability are available from IBM.

Affected products

  • IBM Db2 Mirror for i 7.4, 7.5, 7.6

Timeline

  • 2026-08-14: disclosed

References

Related threats