CVE-2026-16961: IBM i is Affected By SQL Injection Vulnerability in Db2 Mirror []
IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Other sources
IBM i is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.6Patch SJ10902 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.5Patch SJ10908 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.4Patch SJ10910
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16961?
CVE-2026-16961 has a high severity rating of 7.6.
How do I fix CVE-2026-16961?
To fix CVE-2026-16961, you should apply the latest security patches provided by IBM for the affected versions of IBM i.
What systems are affected by CVE-2026-16961?
CVE-2026-16961 affects IBM i versions 7.4, 7.5, and 7.6.
What type of vulnerability is identified in CVE-2026-16961?
CVE-2026-16961 is an SQL injection vulnerability that allows unauthorized access to the database.
Can remote attackers exploit CVE-2026-16961?
Yes, a remote attacker could exploit CVE-2026-16961 by sending specially crafted SQL statements to manipulate the database.