Executive brief
IBM Db2 Mirror for i is a database management system with a web-based GUI interface used to administer IBM i systems. A path traversal vulnerability in the file write functionality allows unauthenticated remote attackers to write files to arbitrary locations on the server, potentially enabling code execution, configuration tampering, or denial of service.
Technical details
CVE-2026-17181 is a path traversal vulnerability (CWE-22) in the IBM Db2 Mirror for i GUI that fails to properly validate and restrict file paths during write operations. The vulnerability is exploitable remotely without authentication (AV:N, PR:N) and requires no user interaction, allowing an attacker to construct malicious path parameters with directory traversal sequences (e.g., "../../../") to write files outside the intended restricted directory. A successful exploit could allow the attacker to overwrite critical files, inject malicious code, or degrade system availability. Patches addressing this vulnerability are available from IBM.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, 7.6
Timeline
- 2026-08-14: disclosed