SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-17186 2026-08-14

CVE-2026-17186: IBM Db2 Mirror for i Command Injection Scores CVSS 9.9

"IBM disclosed a critical command injection flaw in Db2 Mirror for i that lets an unauthenticated remote attacker execute arbitrary CL commands on affected IBM i systems."

IBM disclosed a critical command injection flaw in Db2 Mirror for i that lets an unauthenticated remote attacker execute arbitrary CL commands on affected IBM i systems.

What Is It

CVE-2026-17186 is an improper neutralization of special elements in a command (CWE-78, OS command injection) affecting IBM Db2 Mirror for i. Per IBM's advisory, the product "could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command."

IBM PSIRT assigned a CVSS 3.1 base score of 9.9 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H. The vector describes network-reachable attacks of low complexity requiring no privileges and no user interaction, with a changed scope and high availability impact.

Why It Matters

The combination of no authentication, no user interaction, and network attack vector means exploitation requires nothing more than reachability. The changed scope in the CVSS vector indicates impact extends beyond the vulnerable component itself.

The severity here is driven by availability rather than by full system takeover. CL is IBM i's native control language, so an attacker gains the ability to run commands on the host, but IBM's own scoring rates both confidentiality and integrity impact as Low (C:L/I:L) against a High availability impact (A:H), which describes constrained data exposure and modification alongside the ability to disrupt the service. IBM has not published exploitation details, so the precise privilege context of the injected commands is not established from the advisory.

Db2 Mirror for i is a high-availability replication technology, so affected nodes are typically production database systems. A vulnerability whose dominant impact is availability loss is particularly consequential in a component whose purpose is keeping databases available.

CVE-2026-17186 does not appear in CISA's Known Exploited Vulnerabilities catalog as of 2026-08-14, and no vendor or third-party reporting of in-the-wild exploitation has been published. Active exploitation is not confirmed at this time.

What's Vulnerable

IBM Db2 Mirror for i, versions:

This affected-version list comes from IBM's advisory. Because the NVD record has not completed analysis, no NVD-assigned CPE applicability statements are available for this CVE yet, and defenders should scope exposure from IBM's version list rather than from automated CPE matching.

Patch Status

IBM published a support advisory at node 7283359 covering this issue; administrators should consult it for fix packs and remediation guidance applicable to their release. Because the CVE is absent from the CISA KEV catalog, no BOD 22-01 remediation deadline applies to federal civilian agencies; patching should be prioritized on the CVSS severity and on the exposure of the affected nodes.

The NVD record is in Received status as of 2026-08-14, meaning NVD analysis is incomplete and details may change. The CVSS score shown originates from IBM PSIRT, not NVD analysts.

Sources