What is CVE-2026-18554?
This vulnerability affects IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. A remote authenticated attacker could obtain sensitive information due to improper limitation of a pathname to a restricted directory. Applying the security updates provided by IBM is recommended for affected systems.
Azərbaycanca: Bu zəiflik IBM Db2 Mirror for i məhsulunda aşkarlanıb, 7.4, 7.5 və 7.6 versiyalarına təsir edir. Uzaqdan autentifikasiya olunmuş təcavüzkar məhdudlaşdırılmış kataloq yolunun düzgün idarə edilməməsi səbəbindən həssas məlumat əldə edə bilər. Təsirə məruz qalan sistemlərdə IBM tərəfindən təqdim edilən təhlükəsizlik yeniləmələrinin tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: IBM
FAQ2
Which product is affected by CVE-2026-18554?
This vulnerability affects IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6.
What can an attacker obtain by exploiting CVE-2026-18554?
A remote authenticated attacker could obtain sensitive information due to improper limitation of a pathname to a restricted directory.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.