Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-87958
IBM Db2 vulnerability analysis and mitigation

Overview

CVE-2026-87958 is a denial-of-service vulnerability in IBM Db2 caused by improper privilege management (CWE-269). It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5, allowing a low-privileged authenticated user to disable specific server functionality under certain conditions. The vulnerability was published on September 10, 2026, with the GitHub Advisory Database entry added on September 11, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, IBM Support).

Technical details

The root cause is classified as CWE-269 (Improper Privilege Management), where IBM Db2 fails to properly restrict or validate the actions a low-privileged user can perform against specific server functionality. The attack vector is network-based, requiring only low privileges and no user interaction, with low attack complexity. Under certain unspecified conditions, a privileged (but low-privilege) user can invoke operations that disable a specific Db2 server feature, resulting in a denial-of-service condition. No technical write-ups or proof-of-concept code have been publicly disclosed at this time (GitHub Advisory, IBM Support).

Impact

Successful exploitation results in high integrity and high availability impacts, with no confidentiality impact. A low-privileged network user can disable specific functionality on an affected Db2 server, potentially disrupting database services and dependent applications. While lateral movement is not directly implied, service disruption to a critical database server could cascade to dependent business systems and workflows (GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The NVD SSVC assessment confirms exploitation is currently "none" and the attack is not automatable. The EPSS score is approximately 0.21% (11th percentile), indicating a low near-term probability of exploitation. CVE-2026-87958 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, IBM Support).

Mitigation and workarounds

IBM has published a support advisory for this vulnerability; organizations should consult the IBM support page for specific fix pack or interim fix details (IBM Support). As interim mitigations, restrict network access to Db2 servers to trusted hosts only, and limit administrative and privileged user accounts to the minimum necessary personnel. Monitor Db2 servers for unexpected service disruptions or unusual administrative commands. Apply IBM-provided patches or fix packs as soon as they are available for the affected 11.5.x and 12.1.x release lines.

Additional resources


SourceThis report was generated using AI

Related IBM Db2 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-87958HIGH8.1
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 10, 2026
CVE-2026-15955HIGH7.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 14, 2026
CVE-2026-86093HIGH7.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 10, 2026
CVE-2026-17463MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 14, 2026
CVE-2026-16702MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management