What is CVE-2026-13361?
CVE-2026-13361 is a remote code execution (RCE) vulnerability in IBM Informix, affecting the 'oninit' process's 'sq_sgkprepare' function due to an unchecked length field in the SQL Interface. This flaw could allow an attacker to execute arbitrary code on the affected system. Immediate patching with the vendor's security update is required.
Azərbaycanca: CVE-2026-13361: IBM Informix verilənlər bazasında "oninit" prosesinin "sq_sgkprepare" funksiyasında SQL Interface length sahəsinin yoxlanılmaması səbəbindən uzaqdan kod icrası (RCE) zəifliyi aşkarlanıb. Bu zəiflik təsirlənən sistem üzərində hücumçuya ixtiyari kod icra etməyə imkan verir. Dərhal IBM tərəfindən təqdim olunan təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: IBM
FAQ2
In which component of IBM Informix was the CVE-2026-13361 vulnerability discovered?
The vulnerability was discovered in the 'sq_sgkprepare' function of the 'oninit' process in the IBM Informix database, due to an unchecked length field in the SQL Interface.
What can an attacker achieve by successfully exploiting CVE-2026-13361?
An attacker could execute arbitrary code on the affected system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.