Junglewise Threat Intelligence

CVE-2026-18554: IBM Db2 Mirror for i path traversal information disclosure

CVE-2026-18554 · Severity: high · CVSS 7.5 · Published 2026-08-14

Executive brief

IBM Db2 Mirror for i is a database mirroring and high availability solution used to protect business-critical data and ensure continuous database availability. An authenticated attacker can exploit a path traversal flaw in the GUI to access sensitive files outside intended directories, potentially exposing configuration data, credentials, or other protected information stored on the system.

Technical details

The vulnerability is a path traversal flaw (CWE-22: Improper Limitation of a Pathname to a Restricted Directory) in IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. An authenticated remote attacker can manipulate file path parameters in the GUI to traverse directory boundaries and read files outside the intended restricted directory. The attack requires authentication and network access to the Db2 Mirror for i interface. Successful exploitation allows an attacker to obtain sensitive information stored on the system. Patch availability should be verified through IBM's security bulletins.

Affected products

  • IBM Db2 Mirror for i 7.4, 7.5, 7.6

Timeline

  • 2026-08-14: disclosed

References

Related threats