Junglewise Threat Intelligence

CVE-2026-3623: IBM Netezza Performance Server Replication Services privilege escalation

CVE-2026-3623 · Severity: high · CVSS 7.8 · Published 2026-05-27

Vendors: IBM.

Executive brief

IBM Netezza Performance Server Replication Services, a tool used for data synchronization across database systems, contains a vulnerability that allows a user with low-level access to gain full administrative (root) control. An attacker who has already gained a foothold on the system can use this flaw to take over the entire server, modify or delete critical data, and install persistent backdoors. This could lead to a complete loss of data confidentiality and system availability.

Technical details

A privilege escalation vulnerability exists in IBM Netezza Performance Server Replication Services versions 3.0.2.0 through 3.0.5.0 due to execution with unnecessary privileges (CWE-250). A local attacker with low-privileged access can exploit this flaw to execute commands with root authority. Successful exploitation allows the attacker to obtain a root shell, change the root password, and modify or delete system-wide files. This leads to a total compromise of the host's confidentiality, integrity, and availability. IBM has released version 3.0.5.1 to address this vulnerability.

Affected products

  • IBM Netezza Performance Server Replication Services 3.0.2.0 - 3.0.5.0

Timeline

  • 2026-05-07: advisory: Initial publication by IBM
  • 2026-05-27: disclosed: NVD publication date

References