CVE-2026-10543: IBM® Db2® is vulnerable to privilege escalation with a specially crafted query
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
Other sources
IBM Db2 is vulnerable to privilege escalation with a specially crafted query.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 V11.5 (impacted releases 11.5.0 through 11.5.9)to a version that resolves this vulnerability.Fixed in V11.5.9 - Upgrade
Upgrade
IBM Db2 V12.1 (impacted releases 12.1.0 through 12.1.5)to a version that resolves this vulnerability.Fixed in V12.1.4 - Upgrade
Upgrade
IBM Db2 V12.1.5to a version that resolves this vulnerability.Fixed in V12.1.5Patch Security Update #88454 - Compensating control
For the interim remediation, use the security update containing the interim fix for the issue from Fix Central, as referenced in the provided IBM statement (Security Update #88454 or later for V12.1.5).
- Operational
After applying the security update, verify the Db2 environment is on the latest levels specified by IBM for remediation (V11.5.9, V12.1.4, or V12.1.5) for the impacted release you run.