Executive brief
IBM Db2 Mirror for i is a database management tool used to manage IBM i system data. CVE-2026-17186 allows remote attackers without authentication to execute arbitrary CL (Control Language) system commands on the affected server due to improper input validation, potentially leading to complete system compromise, data theft, or service disruption.
Technical details
This vulnerability is an OS command injection (CWE-78) affecting the GUI component of IBM Db2 Mirror for i. The flaw stems from improper neutralization of special elements in commands, allowing unauthenticated remote attackers to inject and execute arbitrary CL commands over the network without requiring valid credentials. The attack requires no user interaction and has low attack complexity, affecting confidentiality, integrity, and availability. A patch is available from IBM; affected versions include 7.4, 7.5, and 7.6.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, 7.6
Timeline
- 2026-08-14: disclosed