Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-10543: IBM Db2 allows attackers to gain elevated access
CVE-2026-10543 · published 22 days ago
Summary
Certain versions of IBM Db2 are vulnerable to a security weakness that could allow an attacker to gain more access to the database than they should have. This matters because it could allow unauthorized changes to sensitive data. To protect yourself, apply the latest updates to IBM Db2.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | db2 |
<= 11.5.9 >= 11.5, <= 11.5.9 >= 12.1.0, <= 12.1.5 |
Original advisory text
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
References
- https://www.ibm.com/support/pages/node/7282949 vendor-advisory patch
Severity
9.8
Critical
CVSS 3.1: 8.2 (MITRE)
Exploitation
EPSS <1%
Type
CWE-285Improper Authorization
Timeline
Published12 Aug 2026
Updated29 Aug 2026
First seen12 Aug 2026
Monitor software like this
Free during beta