CVE-2026-86087: IBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the system
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.
Other sources
IBM Db2 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2to a version that resolves this vulnerability.Fixed in 11.5.0 through 11.5.9Patch Security Update #89304 or later for V12.1.5 - Upgrade
Upgrade
IBM Db2to a version that resolves this vulnerability.Fixed in 12.1.0 through 12.1.5Patch Security Update #89304 or later for V12.1.5 - Upgrade
Upgrade
IBM Db2to a version that resolves this vulnerability.Fixed in 12.1.5Patch Security Update #89304 or later for V12.1.5
Event History
Frequently Asked Questions
Which Db2 releases are affected?
The affected releases are Db2 11.5.0 through 11.5.9 and Db2 12.1.0 through 12.1.5.
What access does an attacker need?
An attacker must be authenticated to Db2 and able to send a specially crafted request. The provided information does not indicate that unauthenticated attackers can exploit this issue.
What is the likely impact of successful exploitation?
A successful attacker could write arbitrary files on the system. The provided severity vector indicates integrity impact, with no stated confidentiality or availability impact.