CVE-2026-1352: IBM® Db2® is vulnerable to a trap or return SQLCODE -901 when compiling a specially crafted query with a defined index
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1352?
CVE-2026-1352 is categorized as a denial of service vulnerability.
How do I fix CVE-2026-1352?
To mitigate CVE-2026-1352, update IBM Db2 to a version later than 11.5.9 or 12.1.4.
What are the affected versions in CVE-2026-1352?
CVE-2026-1352 affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4.
Can CVE-2026-1352 be exploited by unauthenticated users?
No, CVE-2026-1352 can only be exploited by authenticated users.
What impact does CVE-2026-1352 have on Db2 systems?
CVE-2026-1352 can cause a denial of service condition, leading to potential disruption of database services.