Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-86087
IBM Db2 vulnerability analysis and mitigation

Overview

CVE-2026-86087 is a path traversal vulnerability in IBM Db2 that allows an authenticated user to send a specially crafted request to write arbitrary files on the system. It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5. The vulnerability was published on September 10, 2026, and a patch was made available shortly after. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, IBM Advisory).

Technical details

The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'), where the application fails to properly neutralize special elements within a pathname, allowing it to resolve outside a restricted directory. An authenticated, low-privileged attacker can exploit this by sending a specially crafted network request that manipulates file path parameters to write files to arbitrary locations on the system. Exploitation does not require user interaction and has low attack complexity, but does require valid credentials. Relevant attack patterns include CAPEC-126 (Path Traversal), CAPEC-64 (Using Slashes and URL Encoding to Bypass Validation), and CAPEC-76 (Manipulating Web Input to File System Calls) (GitHub Advisory, IBM Advisory).

Impact

Successful exploitation allows a low-privileged authenticated attacker to write arbitrary files to the Db2 host system, posing an integrity risk. While the CVSS score reflects only a low integrity impact with no direct confidentiality or availability impact, arbitrary file write primitives can potentially be chained to achieve code execution (e.g., by overwriting configuration files, scripts, or scheduled task definitions). The scope is limited to the affected Db2 instance, but lateral movement or privilege escalation may be possible depending on the file system permissions of the Db2 service account (GitHub Advisory, IBM Advisory).

Exploitability

There is currently no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.22%, placing it in the 14th percentile for exploitation likelihood within 30 days. The NVD SSVC assessment classifies exploitation as 'none' and the attack as not automatable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Authentication: Obtain valid low-privileged credentials for the target IBM Db2 instance (e.g., through credential stuffing, phishing, or insider access).
  2. Reconnaissance: Identify the Db2 version to confirm it falls within the affected range (11.5.0–11.5.9 or 12.1.0–12.1.5) using Db2 administrative interfaces or banner information.
  3. Craft malicious request: Construct a specially crafted network request that includes path traversal sequences (e.g., ../../) in a file path parameter accepted by the Db2 service, targeting a writable directory outside the intended restricted path.
  4. Write arbitrary file: Submit the crafted request to the Db2 service endpoint. If successful, the server writes attacker-controlled content to the specified arbitrary path on the file system.
  5. Escalate impact (optional): Depending on the Db2 service account's permissions, overwrite sensitive files (e.g., cron jobs, startup scripts, configuration files) to achieve persistence or code execution (GitHub Advisory, IBM Advisory).

Indicators of compromise

  • Network: Unusual or malformed HTTP/TCP requests to Db2 service ports containing path traversal sequences (e.g., ../, %2e%2e%2f, ..%5c) in request parameters.
  • File System: Unexpected files created in directories outside the Db2 data or installation directories; modification timestamps on system files (e.g., cron jobs, shell scripts) coinciding with Db2 service activity.
  • Logs: Db2 diagnostic logs (db2diag.log) showing errors or anomalies related to file path resolution; OS-level audit logs recording file creation events by the Db2 service account in unexpected directories.
  • Process: Db2 service account spawning unexpected child processes or accessing file paths outside normal operational scope.

Mitigation and workarounds

IBM has released patches addressing this vulnerability; users should upgrade IBM Db2 to a version beyond 11.5.9 (for the 11.5.x line) or beyond 12.1.5 (for the 12.1.x line) (IBM Advisory). As interim mitigations, restrict network access to Db2 instances to only trusted and necessary users and systems, and implement network segmentation to limit exposure. Apply the principle of least privilege to Db2 service accounts to reduce the impact of any successful file write attempt.

Additional resources


SourceThis report was generated using AI

Related IBM Db2 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-87958HIGH8.1
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 10, 2026
CVE-2026-15955HIGH7.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 14, 2026
CVE-2026-86093HIGH7.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 10, 2026
CVE-2026-17463MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 14, 2026
CVE-2026-16702MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management