
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-87958 is a denial-of-service vulnerability in IBM Db2 caused by improper privilege management (CWE-269). It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5, allowing a low-privileged authenticated user to disable specific server functionality under certain conditions. The vulnerability was published on September 10, 2026, with the GitHub Advisory Database entry added on September 11, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, IBM Support).
The root cause is classified as CWE-269 (Improper Privilege Management), where IBM Db2 fails to properly restrict or validate the actions a low-privileged user can perform against specific server functionality. The attack vector is network-based, requiring only low privileges and no user interaction, with low attack complexity. Under certain unspecified conditions, a privileged (but low-privilege) user can invoke operations that disable a specific Db2 server feature, resulting in a denial-of-service condition. No technical write-ups or proof-of-concept code have been publicly disclosed at this time (GitHub Advisory, IBM Support).
Successful exploitation results in high integrity and high availability impacts, with no confidentiality impact. A low-privileged network user can disable specific functionality on an affected Db2 server, potentially disrupting database services and dependent applications. While lateral movement is not directly implied, service disruption to a critical database server could cascade to dependent business systems and workflows (GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The NVD SSVC assessment confirms exploitation is currently "none" and the attack is not automatable. The EPSS score is approximately 0.21% (11th percentile), indicating a low near-term probability of exploitation. CVE-2026-87958 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, IBM Support).
IBM has published a support advisory for this vulnerability; organizations should consult the IBM support page for specific fix pack or interim fix details (IBM Support). As interim mitigations, restrict network access to Db2 servers to trusted hosts only, and limit administrative and privileged user accounts to the minimum necessary personnel. Monitor Db2 servers for unexpected service disruptions or unusual administrative commands. Apply IBM-provided patches or fix packs as soon as they are available for the affected 11.5.x and 12.1.x release lines.
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"