CVE-2026-10535 – IBM Db2

CVSS 8.4 IMPORTANT High with EoP or RCE – Expedited Deployment

“A single memory handling flaw in a privileged helper can undermine the security of an entire database environment.”

This patch addresses CVE-2026-10535, a Stack-Based Buffer Overflow vulnerability (CWE-121) affecting IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4. The CVSS score is 8.4, which is High severity. No verified real-world exploitation has been reported.

The vulnerability exists in the setgid helper db2flacc, where improper memory handling can result in a buffer overflow. Successful exploitation could allow arbitrary code execution within the affected environment. Based on the supplied assessment, the vulnerability has Remote Code Execution (RCE) characteristics but does not have Elevation of Privilege (EoP) characteristics. IBM has released security updates to address the flaw, and organizations running affected Db2 versions should apply the update promptly.

Key Details

Affected Product
Ibm Db2
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-121
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.