Executive brief
IBM Db2 Mirror for i is a database replication and recovery solution used to protect critical business data. A remote authenticated attacker can exploit a path traversal vulnerability to delete arbitrary files from the system, potentially causing data loss or service disruption.
Technical details
CVE-2026-18178 is a path traversal vulnerability in IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 that allows deletion of arbitrary files. The vulnerability exists due to improper limitation of a pathname to a restricted directory (CWE-22). An authenticated attacker with network access can exploit this vulnerability without user interaction to delete files outside the intended directory, potentially compromising data integrity and system availability. IBM has released security updates to address this issue.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, and 7.6
Timeline
- 2026-08-14: disclosed