
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1352 is a denial-of-service vulnerability in IBM Db2 for Linux, UNIX, and Windows (including Db2 Connect Server) caused by improper neutralization of special elements in data query logic. It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4, as well as IBM Application Performance Management products that bundle Db2. The vulnerability was disclosed on April 23, 2026, with IBM publishing its security bulletin on April 15, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (IBM Advisory, GitHub Advisory).
The root cause is classified as CWE-1284 (Improper Validation of Specified Quantity in Input), where the product fails to properly validate quantities or special elements provided in query input. Specifically, IBM's advisory describes the issue as causing a trap or return of SQLCODE -901 when the Db2 engine compiles a specially crafted query that references a defined index, indicating a fault in the query compilation path. Exploitation requires network access and low-level authenticated privileges, with no user interaction needed. No public proof-of-concept code has been identified at this time (IBM Advisory, GitHub Advisory).
Successful exploitation allows an authenticated remote attacker to crash the Db2 database engine, resulting in a denial-of-service condition that disrupts database availability. There is no impact on data confidentiality or integrity, as the vulnerability solely affects availability. Environments relying on Db2 for critical business operations — including those using IBM Application Performance Management products bundled with Db2 — are at risk of service interruption (IBM Advisory, GitHub Advisory).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-1352. The EPSS score is approximately 0.044–0.061%, placing it in a low exploitation probability range (around the 19th percentile). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access to the Db2 instance, which limits the attack surface compared to unauthenticated vulnerabilities (IBM Advisory, GitHub Advisory).
db2diag.log) showing SQLCODE -901 errors or trap messages during query compilation; repeated error entries referencing index-related query compilation failures.db2sysc process terminating abnormally.IBM has released patches addressing this vulnerability; users should apply the fixes referenced in IBM security bulletin node/7269433 for Db2 11.5.x and 12.1.x. A separate advisory (node/7273649) addresses the vulnerability in IBM Application Performance Management products bundling Db2. As a general workaround, restrict database access to trusted, authorized users only and monitor for anomalous query patterns. Upgrading to a patched Db2 fix pack is the recommended remediation (IBM Advisory, IBM APM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."