← Vulnerability feed

Vulnerability record · CVE-2026-17182 · published 14 August 2026

CVE-2026-17182: Ibm db2 mirror for i improper authentication vulnerability

Ibm · Db2 Mirror For I

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.

9.8 CVSS 3.1 Critical EPSS 0.73% · top 47.7% CWE-287 · Improper authentication
9.8CVSS 3.1 base score
0.73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
20 Aug 2026Last modified by NVD

Description

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-17182 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-17184Ibm db2 mirror for i vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.EPSS 0.80%9.8CVE-2026-17186Ibm db2 mirror for i os command injection vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special eleme…EPSS 0.50%9.8CVE-2026-16956Ibm db2 mirror for i os command injection vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements…EPSS 0.86%8.8CVE-2026-16879Ibm db2 mirror for i improper authorization vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization usin…EPSS 0.50%8.6CVE-2026-17181Ibm db2 mirror for i path traversal vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.EPSS 0.55%8.1CVE-2026-18178Ibm db2 mirror for i path traversal vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.EPSS 0.54%7.5CVE-2026-18554Ibm db2 mirror for i path traversal vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pa…EPSS 0.85%7.5CVE-2026-17081Ibm db2 mirror for i path traversal vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricte…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2026-17182), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.