ZeroHour

CVE-2026-87958

large

Privileged-user denial-of-service flaw in IBM Db2 11.5 and 12.1

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 contain a denial-of-service vulnerability (CWE-269, improper privilege management) in which a specific functionality on a Db2 server can be disabled. The flaw is triggered over the network by an authenticated user holding privileges on the Db2 server — the CVSS vector grades required privileges as low (PR:L) — and requires no user interaction, under certain conditions on the server. A successful attacker can disable that functionality, hitting availability; the 8.1 High CVSS vector also scores high integrity impact (C:N/I:H/A:H), suggesting the affected functionality can be left in a modified or disabled state. Any organization running the listed Db2 11.5.x or 12.1.x releases is potentially affected, though exploitation requires an account with privileges on the database server. There is no evidence of exploitation: the flaw is not in CISA KEV, and no public proof-of-concept is known.

What to do: Check IBM's PSIRT advisory for CVE-2026-87958 to identify the fixed fix pack or interim-fix level (not specified in the available data) and plan upgrades for all 11.5.x and 12.1.x Db2 deployments. As an interim mitigation, restrict which accounts hold administration privileges on Db2 servers and audit recent configuration changes to the affected functionality. Prioritize systems where low-privileged or shared accounts can reach the database over the network.

Affected
IBM Db211.5.0 through 11.5.9
IBM Db212.1.0 through 12.1.5
Estimated exposure
largeon the order of tens of thousands of enterprise database instances (exact count unknown; no install-base figure in the data) — IBM Db2 is a mainstream enterprise RDBMS with a large install base in banking, ERP and other back-office workloads, but it is typically deployed as internal database servers rather than internet-exposed services, so the exposed/attackable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

Vendors
ibm
Products
db2
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.