CVE-2026-3676: There are multiple vulnerabilities in IBM DB2 bundled with IBM Application Performance Management products.
IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced environment.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3676?
The severity of CVE-2026-3676 is medium, rated at 6.5.
How do I fix CVE-2026-3676?
To fix CVE-2026-3676, apply the necessary fixes to your DB2 V11.5 server as indicated in the security bulletins.
What products are affected by CVE-2026-3676?
CVE-2026-3676 affects IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4.
What type of vulnerability is CVE-2026-3676?
CVE-2026-3676 is a denial of service vulnerability due to improper neutralization of special elements in the data query logic.
Who can exploit CVE-2026-3676?
An authenticated user can exploit CVE-2026-3676 to cause a denial of service.