← Vulnerability feed

Vulnerability record · CVE-2026-18104 · published 24 September 2026

CVE-2026-18104: Ibm db2 mirror for i broken cryptographic algorithm vulnerability

Ibm · Db2 Mirror For I

IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.

3.3 CVSS 3.1 Low EPSS 0.06% · top 100.0% CWE-327 · Broken cryptographic algorithm
3.3CVSS 3.1 base score
0.06%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
29 Sep 2026Last modified by NVD

Description

IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.ibm.com/support/pages/node/7289246 PatchVendor Advisory

Track CVE-2026-18104 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-17184Ibm db2 mirror for i vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.EPSS 0.80%9.8CVE-2026-17186Ibm db2 mirror for i os command injection vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special eleme…EPSS 0.50%9.8CVE-2026-17182Ibm db2 mirror for i improper authentication vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improp…EPSS 0.73%9.8CVE-2026-16956Ibm db2 mirror for i os command injection vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements…EPSS 0.86%8.8CVE-2026-16879Ibm db2 mirror for i improper authorization vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization usin…EPSS 0.50%8.6CVE-2026-17181Ibm db2 mirror for i path traversal vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.EPSS 0.55%8.1CVE-2026-18178Ibm db2 mirror for i path traversal vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.EPSS 0.54%7.5CVE-2026-18554Ibm db2 mirror for i path traversal vulnerabilityIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pa…EPSS 0.85%

Source: NIST National Vulnerability Database (record CVE-2026-18104), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.