Junglewise Threat Intelligence

CVE-2026-17184: IBM Db2 Mirror for i external control of file name or path

CVE-2026-17184 · Severity: critical · CVSS 9.8 · Published 2026-08-14

Technologies: IBM Db2 Mirror For I. Vendors: IBM.

Executive brief

IBM Db2 Mirror for i is a database management and replication tool used by enterprises to protect critical data. A remote attacker can exploit a file path control vulnerability to execute arbitrary code on vulnerable systems, potentially leading to complete system compromise, data theft, and operational disruption without requiring authentication or user interaction.

Technical details

The vulnerability is a CWE-73 (External Control of File Name or Path) issue affecting IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. The GUI component fails to properly validate or restrict file name and path inputs, allowing a remote attacker to supply malicious file paths that can be used to execute arbitrary code. This is a network-reachable vulnerability requiring no authentication or user interaction; the attacker can directly manipulate file paths via the web-based interface. Exploitation results in full system compromise with high impact to confidentiality, integrity, and availability. IBM has issued security fixes; users should apply patches immediately.

Affected products

  • IBM Db2 Mirror for i 7.4, 7.5, 7.6

Timeline

  • 2026-08-14: disclosed

References

Related threats