Junglewise Threat Intelligence

CVE-2026-87958: IBM Db2 denial of service via privilege management

CVE-2026-87958 · Severity: high · CVSS 8.1 · Published 2026-09-10

Technologies: IBM Db2. Vendors: IBM.

Executive brief

IBM Db2 is a relational database server used by enterprises to store and manage critical business data. A DBADM-privileged attacker (typically a database administrator) can exploit this vulnerability to disable specific database functionality and cause service unavailability under certain conditions. This impacts business operations and data availability, though it requires administrative privileges to execute.

Technical details

The vulnerability is a privilege management flaw (CWE-269) affecting Db2 versions 11.5.0–11.5.9 and 12.1.0–12.1.5. A user with DBADM (database administrator) authority can disable specific Db2 server functionality under certain conditions, leading to denial of service. The attack requires network access and valid DBADM credentials; no user interaction is needed. IBM has not disclosed the specific functionality affected or detailed attack steps to prevent weaponization. Patches are available via IBM security updates for V11.5.9, V12.1.4, and V12.1.5.

Affected products

  • IBM Db2 11.5.0 through 11.5.9, 12.1.0 through 12.1.5

Timeline

  • 2026-09-10: disclosed: Initial publication of security bulletin
  • 2026-09-16: advisory: Title and summary updated to specify DBADM privilege requirements

References

Related threats