Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-10543: IBM Db2 allows attackers to gain elevated access

CVE-2026-10543 · published 22 days ago
Summary

Certain versions of IBM Db2 are vulnerable to a security weakness that could allow an attacker to gain more access to the database than they should have. This matters because it could allow unauthorized changes to sensitive data. To protect yourself, apply the latest updates to IBM Db2.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm db2 <= 11.5.9
>= 11.5, <= 11.5.9
>= 12.1.0, <= 12.1.5
Original advisory text
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
References
Severity
9.8 Critical
CVSS 3.1: 8.2 (MITRE)
Exploitation
EPSS <1%
Type
CWE-285Improper Authorization
Timeline
Published12 Aug 2026
Updated29 Aug 2026
First seen12 Aug 2026
Sources
CVE-2026-10543 · MITRE
Monitor software like this
Free during beta