
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-86087 is a path traversal vulnerability in IBM Db2 that allows an authenticated user to send a specially crafted request to write arbitrary files on the system. It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5. The vulnerability was published on September 10, 2026, and a patch was made available shortly after. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, IBM Advisory).
The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'), where the application fails to properly neutralize special elements within a pathname, allowing it to resolve outside a restricted directory. An authenticated, low-privileged attacker can exploit this by sending a specially crafted network request that manipulates file path parameters to write files to arbitrary locations on the system. Exploitation does not require user interaction and has low attack complexity, but does require valid credentials. Relevant attack patterns include CAPEC-126 (Path Traversal), CAPEC-64 (Using Slashes and URL Encoding to Bypass Validation), and CAPEC-76 (Manipulating Web Input to File System Calls) (GitHub Advisory, IBM Advisory).
Successful exploitation allows a low-privileged authenticated attacker to write arbitrary files to the Db2 host system, posing an integrity risk. While the CVSS score reflects only a low integrity impact with no direct confidentiality or availability impact, arbitrary file write primitives can potentially be chained to achieve code execution (e.g., by overwriting configuration files, scripts, or scheduled task definitions). The scope is limited to the affected Db2 instance, but lateral movement or privilege escalation may be possible depending on the file system permissions of the Db2 service account (GitHub Advisory, IBM Advisory).
There is currently no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.22%, placing it in the 14th percentile for exploitation likelihood within 30 days. The NVD SSVC assessment classifies exploitation as 'none' and the attack as not automatable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
../../) in a file path parameter accepted by the Db2 service, targeting a writable directory outside the intended restricted path.../, %2e%2e%2f, ..%5c) in request parameters.db2diag.log) showing errors or anomalies related to file path resolution; OS-level audit logs recording file creation events by the Db2 service account in unexpected directories.IBM has released patches addressing this vulnerability; users should upgrade IBM Db2 to a version beyond 11.5.9 (for the 11.5.x line) or beyond 12.1.5 (for the 12.1.x line) (IBM Advisory). As interim mitigations, restrict network access to Db2 instances to only trusted and necessary users and systems, and implement network segmentation to limit exposure. Apply the principle of least privilege to Db2 service accounts to reduce the impact of any successful file write attempt.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."