CVE-2026-1352
published 2026-04-23CVE-2026-1352: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a…
PriorityP432medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.33%
24.8th percentile
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | 11.5.0 – 11.5.9 | — |
| ibm | db2 | 12.1.0 – 12.1.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM DB2/DB2 Connect Server up to 11.5.9/12.1.4 improper validation of specified quantity in input (Nessus ID 310109 / CNNVD-202604-4732)
vuldb·2026-04-25·CVSS 6.5
CVE-2026-1352 [MEDIUM] IBM DB2/DB2 Connect Server up to 11.5.9/12.1.4 improper validation of specified quantity in input (Nessus ID 310109 / CNNVD-202604-4732)
A vulnerability was found in IBM DB2 and DB2 Connect Server up to 11.5.9/12.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to improper validation of specified quantity in input.
This vulnerability is tracked as CVE-2026-1352. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
GHSA-chwf-7mw9-8249: IBM Db2 11
ghsa_unreviewed·2026-04-23
CVE-2026-1352 [MEDIUM] CWE-1284 GHSA-chwf-7mw9-8249: IBM Db2 11
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-23
Published