CVE-2026-9762 – IBM Db2

CVSS 7.8 IMPORTANT High with EoP or RCE – Expedited Deployment

“User-controlled connection settings should never become a path to code execution.”

IBM has released an update for Db2 to address CVE-2026-9762, a high-severity vulnerability affecting IBM Db2 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4. The vulnerability could allow remote code execution when a JDBC URL is under user control. The issue is associated with CWE-94 (Improper Control of Generation of Code).

The CVSS score is 7.8, which is High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with this vulnerability.

Key Details

Affected Product
Ibm Db2
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-94
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.