CVE-2026-18178: IBM Db2 Mirror for i is affected by multiple vulnerabilities
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
Other sources
IBM Db2 Mirror for i could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Fixed in 7.4Patch SJ10947 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Fixed in 7.5Patch SJ10948 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ10961
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18178?
CVE-2026-18178 has a medium severity rating of 5.4.
What type of vulnerability is associated with CVE-2026-18178?
CVE-2026-18178 is a path traversal vulnerability.
Who is affected by CVE-2026-18178?
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are affected by CVE-2026-18178.
What can an attacker do with CVE-2026-18178?
An attacker can delete arbitrary files due to the path traversal vulnerability in CVE-2026-18178.
How can I mitigate CVE-2026-18178?
To mitigate CVE-2026-18178, ensure that access controls are in place and regularly update IBM Db2 Mirror for i software.