CVE-2026-13367: IBM Informix Dynamic Server Privilege Escalation Vulnerability in oninit Utility
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.
Other sources
IBM Informix Dynamic Server contain a local privilege escalation vulnerability in the
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Informix Dynamic Serverto a version that resolves this vulnerability.Fixed in 14.10.xC13W13 - Upgrade
Upgrade
IBM Informix Dynamic Serverto a version that resolves this vulnerability.Fixed in 15.0.1.14 - Compensating control
Follow the Informix Servers documentation instructions for Database server upgrades (as referenced for Informix Servers 14.10) when applying the IBM Informix fixes from IBM Fix Central.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13367?
The severity of CVE-2026-13367 is rated as high with a score of 7.8.
How do I fix CVE-2026-13367?
To fix CVE-2026-13367, upgrade to the latest version of IBM Informix Dynamic Server that addresses this vulnerability.
Who is affected by CVE-2026-13367?
CVE-2026-13367 affects users of IBM Informix Dynamic Server versions 14.10 and 15.0.
What type of vulnerability is CVE-2026-13367?
CVE-2026-13367 is a local privilege escalation vulnerability found in the oninit setuid-root utility.
What are the potential impacts of CVE-2026-13367?
The potential impacts of CVE-2026-13367 include unauthorized access and escalation of privileges on systems running vulnerable versions of IBM Informix Dynamic Server.