CVE-2026-86093: IBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certain conditions
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.
Other sources
IBM Db2 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2to a version that resolves this vulnerability.Patch 89304 - Upgrade
Upgrade
IBM Db2to a version that resolves this vulnerability.Fixed in 12.1.5 - Upgrade
Upgrade
IBM Db2to a version that resolves this vulnerability.Fixed in 12.1.4 - Upgrade
Upgrade
IBM Db2to a version that resolves this vulnerability.Fixed in 11.5.9
Event History
Frequently Asked Questions
Which systems are the execution target in this issue?
The described command execution occurs on Db2 clients that process data from a DRDA server endpoint controlled or impersonated by an attacker. The issue is associated with the federated-server scenario.
What capability does an attacker need to exploit this?
The attacker must be able to control or impersonate a DRDA server endpoint. The supplied severity vector also indicates low privileges are required, but does not specify what those privileges are or where they are needed.
Is a default Db2 deployment known to be affected?
The available information does not state whether the vulnerable DRDA interaction is enabled or reachable in a default configuration. Exposure depends on whether affected Db2 clients interact with a DRDA endpoint an attacker can control or impersonate.