IBM disclosed a CVSS 9.8 remote code execution flaw in Db2 Mirror for i versions 7.4, 7.5, and 7.6, caused by external control of a file name or path.
What Is It
CVE-2026-17184 is an external control of file name or path weakness (CWE-73) in IBM Db2 Mirror for i. Per IBM's advisory, the flaw "could allow a remote attacker to execute arbitrary code."
IBM PSIRT rated it CVSS 3.1 base score 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Every exploitability metric is worst-case: network attack vector, low attack complexity, no privileges required, and no user interaction. Impact is high across confidentiality, integrity, and availability, with an exploitability subscore of 3.9 and impact subscore of 5.9.
Why It Matters
An unauthenticated, network-reachable path to arbitrary code execution generally ranks among the highest-value classes of vulnerability an attacker can find. There is no precondition to satisfy; no stolen credential, no phished click. Db2 Mirror for i provides continuous availability and replication for IBM i database environments, so a compromised instance sits directly adjacent to production data.
Note that this record was published 2026-08-14 with NVD status "Received," meaning NVD analysis is not yet complete. CVE-2026-17184 does not appear in the CISA Known Exploited Vulnerabilities catalog as of this writing, so active exploitation has not been confirmed by CISA and no KEV-mandated remediation deadline applies. That absence is not evidence of safety; it likely reflects the recency of the disclosure.
What's Vulnerable
IBM Db2 Mirror for i, the following versions marked affected:
- 7.4 (including 7.4.0)
- 7.5 (including 7.5.0)
- 7.6 (including 7.6.0)
No other IBM products are listed as affected in this record.
Patch Status
IBM has published a support advisory at node 7283359 covering this issue. The supplied record does not specify fixed version numbers or PTF identifiers, so administrators should consult IBM's advisory directly for the applicable remediation for their release level. Given the 9.8 rating and the lack of any authentication requirement, remediation should be treated as urgent rather than routine.
Sources
- NVD, CVE-2026-17184: https://nvd.nist.gov/vuln/detail/CVE-2026-17184
- IBM Support Advisory ([email protected]): https://www.ibm.com/support/pages/node/7283359
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog