Junglewise Threat Intelligence

CVE-2026-17209: IBM Db2 Mirror for i cross-site scripting

CVE-2026-17209 · Severity: medium · CVSS 6.3 · Published 2026-08-14

Technologies: IBM Db2 Mirror For I. Vendors: IBM.

Executive brief

IBM Db2 Mirror for i is a database management tool used by organizations to monitor and manage Db2 databases on IBM i systems. The vulnerability allows an authenticated attacker to inject malicious scripts that execute in the context of another user's browser session when they interact with the GUI, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.

Technical details

This is a reflected or stored cross-site scripting (XSS) vulnerability in IBM Db2 Mirror for i's web GUI (CWE-79), where user input is not properly neutralized during web page generation. The vulnerability requires authentication to the system and user interaction (clicking a malicious link or opening a crafted page), but allows an attacker to execute arbitrary JavaScript in the victim's browser context. An authenticated attacker can craft a malicious request that, when clicked by a targeted user, injects scripts that steal session cookies, perform unauthorized actions, or deface the interface. IBM has published a security bulletin addressing this and multiple related vulnerabilities in versions 7.4, 7.5, and 7.6.

Affected products

  • IBM Db2 Mirror for i 7.4, 7.5, 7.6

Timeline

  • 2026-08-14: disclosed

References

Related threats