
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-10109 is a critical remote code execution (RCE) vulnerability in IBM Db2 caused by improper handling of the pre-authentication DRDA (Distributed Relational Database Architecture) handshake. It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4. The vulnerability was disclosed on June 23, 2026, with IBM publishing its security bulletin and the CVE being published to NVD on June 30, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (IBM Advisory, GitHub Advisory).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), arising from insufficient validation during the DRDA protocol handshake phase that occurs before any authentication takes place. Because the flaw exists in the pre-authentication handshake, an unauthenticated remote attacker can send a specially crafted DRDA connection request to the Db2 listener port to trigger code injection and achieve arbitrary code execution. No user interaction, privileges, or special network positioning are required — the attack is fully automatable over the network (IBM Advisory, GitHub Advisory).
Successful exploitation grants an unauthenticated remote attacker full control over the affected Db2 instance, resulting in high impact to confidentiality, integrity, and availability. An attacker could exfiltrate sensitive database contents, manipulate or destroy data, crash the database service, or use the compromised server as a pivot point for lateral movement within the network. Given that Db2 is commonly used to store enterprise-critical and regulated data, the potential for significant data breach and business disruption is substantial (IBM Advisory, GitHub Advisory).
db2diag.log) showing errors or exceptions during the DRDA handshake phase; authentication failure logs combined with unusual process spawning events.curl, wget, nc); new processes running under the Db2 service account that are unrelated to normal database operations.IBM has released patches addressing this vulnerability; organizations should upgrade IBM Db2 to a fixed version beyond 11.5.9 (for the 11.5.x line) and beyond 12.1.4 (for the 12.1.x line) as directed in the IBM security bulletin. As an immediate workaround where patching is not immediately possible, restrict network access to Db2 listener ports (50000/TCP, 50001/TCP) using firewalls or network ACLs to limit exposure to trusted hosts only. Organizations should also deploy Nessus plugins 322980 and 322981 to identify vulnerable instances across their environment (IBM Advisory).
Heise Online covered the vulnerability, describing it as a critical client handshake vulnerability threatening IBM Db2 deployments (Heise). Security news outlets including SecurityOnline.info and BeyondMachines.net highlighted the unauthenticated RCE nature of the flaw as particularly concerning given Db2's enterprise database role. Community aggregators such as VulDB and CVEFeed.io catalogued the vulnerability shortly after disclosure, reflecting broad awareness in the security research community.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."