Executive brief
IBM Db2 Mirror for i is a database management system used to administer data storage and access controls. A flaw in how the system validates request paths allows remote attackers to bypass authentication and gain unauthorized access to modify or read sensitive data without valid credentials.
Technical details
CVE-2026-17182 is an authentication bypass vulnerability (CWE-287) in IBM Db2 Mirror for i caused by improper validation of request URI path segments. The flaw allows unauthenticated remote attackers to craft malicious URI requests that bypass authentication checks, resulting in the ability to read or modify sensitive information. The attack requires only network access with no authentication or user interaction; the vulnerability affects versions 7.4, 7.5, and 7.6. Patches or mitigations from IBM are expected but specific remediation details are not provided in the available advisory content.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, 7.6
Timeline
- 2026-08-14: disclosed