
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-9762 is a code injection vulnerability in IBM Db2 that enables remote code execution when a JDBC URL parameter is under user control. It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4. The vulnerability was published on July 17, 2026, and is currently undergoing analysis. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, IBM Support).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection): IBM Db2 fails to properly neutralize or validate user-supplied JDBC URL input before using it in code generation or execution contexts. An attacker with local, low-privileged access who can influence the JDBC URL parameter passed to a Db2 application can inject malicious content that is subsequently executed by the Db2 process. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward to exploit once local access is obtained (GitHub Advisory, IBM Support).
Successful exploitation allows a low-privileged local user to execute arbitrary code with the privileges of the IBM Db2 process, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker could access sensitive database contents, modify or destroy data, and potentially disrupt Db2 service availability. Depending on the privileges of the Db2 process, exploitation could facilitate lateral movement within the environment or escalation to higher system privileges (GitHub Advisory).
db2diag.log) or application logs, particularly those containing unexpected class names, file paths, or remote references.curl, wget, or nc).IBM has published a support page (node/7279479) addressing this vulnerability; users should consult it for specific patch details and apply updates to versions beyond 11.5.9 or 12.1.4 as soon as they become available (IBM Support). As interim mitigations: restrict local system access to only users who require it, implement access controls to prevent untrusted users from modifying JDBC URL configurations used by Db2 applications, and audit any applications that accept JDBC URLs as input to ensure they validate and sanitize such parameters. Principle of least privilege should be enforced for all Db2 service accounts.
The vulnerability was noted by automated vulnerability tracking services including VulDB, Vulners, and ENISA's EUVD shortly after publication on July 17, 2026. No significant researcher commentary, vendor statements beyond the IBM support page, or notable media coverage has been identified at this time (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."