CVE-2026-13361 – IBM Informix Dynamic Server

CVSS 8.8 IMPORTANT High with EoP or RCE – Expedited Deployment

“Code execution and privilege escalation flaws can turn vulnerable database services into a path for system compromise.”

IBM Informix Dynamic Server is affected by three high-severity vulnerabilities. CVE-2026-13361 involves an unchecked SQL interface length field that can enable remote code execution and has a CVSS score of 8.8, High severity. CVE-2026-13367 affects the oninit setuid-root utility and can enable local privilege escalation. It has a CVSS score of 7.8, High severity.

CVE-2026-13476 can allow an unauthenticated attacker to execute arbitrary commands with service account privileges because of improper input validation. It has a CVSS score of 7.3, High severity.

Key Details

Affected Product
Ibm Informix Dynamic Server
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-121
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.