
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-86093 is a stack-based buffer overflow vulnerability in IBM Db2 that allows an attacker who can control or impersonate a DRDA (Distributed Relational Database Architecture) server endpoint to execute arbitrary commands on Db2 clients. It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5. The vulnerability was published on September 10, 2026, with a GitHub Advisory added on September 11, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, IBM Support).
The root cause is a stack-based buffer overflow (CWE-121) in IBM Db2's DRDA client communication code, where user-controlled data received from a DRDA server endpoint is improperly copied into a fixed-size stack buffer without bounds checking. An attacker must be able to control or impersonate a DRDA server endpoint — for example, via a man-in-the-middle position or by operating a rogue DRDA server — and requires low-level privileges to exploit the flaw. The attack is delivered over the network but has high complexity due to the prerequisite of controlling the DRDA server endpoint. No public proof-of-concept code has been identified (GitHub Advisory, IBM Support).
Successful exploitation allows an attacker to execute arbitrary commands on Db2 client systems, resulting in high confidentiality, integrity, and availability impact. An attacker could fully compromise the affected Db2 client host, potentially enabling lateral movement within the network, exfiltration of sensitive database-related data, or disruption of database client operations. The scope is limited to the client system connecting to the malicious DRDA endpoint, but the total technical impact is classified as complete (GitHub Advisory, IBM Support).
As of the time of disclosure, there is no evidence of active in-the-wild exploitation and no public proof-of-concept exploit has been published (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.47–0.48%, placing it in the 41st percentile for exploitation probability within 30 days. The NVD SSVC assessment notes the vulnerability is not automatable, which limits mass exploitation potential.
db2diag.log) showing connection errors, crashes, or unexpected terminations during DRDA server communication; operating system crash dumps or core files generated by the Db2 client process.IBM has released patches addressing this vulnerability; users should update IBM Db2 to a version beyond 11.5.9 (for the 11.5.x branch) or beyond 12.1.5 (for the 12.1.x branch) as detailed in the IBM support page (IBM Support). As a network-level workaround, restrict DRDA client connections to only trusted, known server endpoints using firewall rules or network access controls, preventing connections to unauthorized DRDA servers. Organizations should also monitor for unauthorized DRDA server connections or suspicious network traffic from Db2 clients connecting to unexpected servers.
Social media activity around CVE-2026-86093 was limited to automated CVE tracking accounts, including posts on Mastodon from @thehackerwire and @vuldb shortly after disclosure. No significant researcher commentary, vendor statements beyond the IBM advisory, or major media coverage has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."