CVE-2026-6938: IBM® Db2® is vulnerable to authorization bypass when uploading to a remote object storage path with a special query
IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 V12.1to a version that resolves this vulnerability.Fixed in V12.1.4 - Operational
Download the special build containing the interim fix for IBM Db2 V12.1 (based on level V12.1.4) from IBM Fix Central and apply it to any affected Db2 instances (IBM Db2 12.1.0 through 12.1.4) to remediate the authorization bypass.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6938?
CVE-2026-6938 has a high severity rating of 7.5.
How do I fix CVE-2026-6938?
To fix CVE-2026-6938, download the special build containing the interim fix from Fix Central for IBM Db2 version 12.1.
What types of attacks does CVE-2026-6938 allow?
CVE-2026-6938 allows authorization bypass, enabling potential unauthorized access to upload to a remote object storage path.
Which versions of IBM Db2 are affected by CVE-2026-6938?
IBM Db2 versions 12.1.0 through 12.1.4 are affected by CVE-2026-6938.
Can CVE-2026-6938 result in data integrity issues?
Yes, CVE-2026-6938 can lead to data integrity issues due to unauthorized modifications allowed by the authorization bypass.