CVE-2026-9762

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
17/07/2026
Last modified:
24/07/2026

Description

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:* 11.5.0 (including) 11.5.9 (including)
cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:* 12.1.0 (including) 12.1.5 (excluding)


References to Advisories, Solutions, and Tools