CVE-2026-13361: IBM Informix Server Vulnerability in SQL Interface Handler Could Allow Remote Code Execution
IBM Informix oninit sqsgkprepare RCE via unchecked SQL Interface length field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Informix Serverto a version that resolves this vulnerability.Fixed in 14.10.xC13W13 - Upgrade
Upgrade
IBM Informix Serverto a version that resolves this vulnerability.Fixed in 15.0.1.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13361?
The severity of CVE-2026-13361 is rated high with a CVSS score of 8.8.
How do I fix CVE-2026-13361?
To fix CVE-2026-13361, users should apply the latest patches and updates provided by IBM for Informix Dynamic Server.
What impact does CVE-2026-13361 have on IBM Informix Server?
CVE-2026-13361 allows for remote code execution due to an unchecked SQL Interface length field.
Which versions of IBM Informix are affected by CVE-2026-13361?
IBM Informix Dynamic Server versions 14.10, 12.10.x, and 15.0 are affected by CVE-2026-13361.
Can CVE-2026-13361 be exploited remotely?
Yes, CVE-2026-13361 can be exploited remotely due to its nature of allowing remote code execution.