Junglewise Threat Intelligence

CVE-2026-17182: IBM Db2 Mirror for i authentication bypass in URI path validation

CVE-2026-17182 · Severity: critical · CVSS 9.8 · Published 2026-08-14

Technologies: IBM Db2 Mirror For I. Vendors: IBM.

Executive brief

IBM Db2 Mirror for i is a database management system used to administer data storage and access controls. A flaw in how the system validates request paths allows remote attackers to bypass authentication and gain unauthorized access to modify or read sensitive data without valid credentials.

Technical details

CVE-2026-17182 is an authentication bypass vulnerability (CWE-287) in IBM Db2 Mirror for i caused by improper validation of request URI path segments. The flaw allows unauthenticated remote attackers to craft malicious URI requests that bypass authentication checks, resulting in the ability to read or modify sensitive information. The attack requires only network access with no authentication or user interaction; the vulnerability affects versions 7.4, 7.5, and 7.6. Patches or mitigations from IBM are expected but specific remediation details are not provided in the available advisory content.

Affected products

  • IBM Db2 Mirror for i 7.4, 7.5, 7.6

Timeline

  • 2026-08-14: disclosed

References

Related threats