CVE-2026-6938
published 2026-05-27CVE-2026-6938: IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.18%
8.3th percentile
IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | 12.1.0 – 12.1.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fmg6-qg6h-pwx6: IBM Db2 12
ghsa_unreviewed·2026-05-27
CVE-2026-6938 [MEDIUM] CWE-285 GHSA-fmg6-qg6h-pwx6: IBM Db2 12
IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.
VulDB
IBM Db2 up to 12.1.4 improper authorization
vuldb·2026-05-27·CVSS 6.5
CVE-2026-6938 [MEDIUM] IBM Db2 up to 12.1.4 improper authorization
A vulnerability marked as critical has been reported in IBM Db2 up to 12.1.4. Affected by this issue is some unknown functionality. This manipulation causes improper authorization.
This vulnerability appears as CVE-2026-6938. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
Citrix
Citrix Security Bulletin CTX140113
vendor_citrix·CVSS 5.0
CVE-2013-6938 [MEDIUM] Citrix Security Bulletin CTX140113
Citrix Security Bulletin CTX140113
CVE References: CVE-2013-6938, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX139049
vendor_citrix·CVSS 5.0
CVE-2013-6938 [MEDIUM] Citrix Security Bulletin CTX139049
Citrix Security Bulletin CTX139049
CVE References: CVE-2013-6938, CVE-2013-6939, CVE-2013-6940, CVE-2013-6941, CVE-2013-6942, CVE-2013-6943, CVE-2013-6944, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-27
Published