CVE-2026-9762
published 2026-07-17CVE-2026-9762: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
PriorityP347high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
13.9th percentile
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | 11.5.0 – 11.5.9 | — |
| ibm | db2 | >= 12.1.0 < 12.1.5 | 12.1.5 |
| ibm | db2 | 12.1.0 – 12.1.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Db2 up to 11.5.9/12.1.4 JDBC os command injection (EUVD-2026-45234 / Nessus ID 330122)
vuldb·2026-07-27·CVSS 7.8
CVE-2026-9762 [HIGH] IBM Db2 up to 11.5.9/12.1.4 JDBC os command injection (EUVD-2026-45234 / Nessus ID 330122)
A vulnerability classified as very critical was found in IBM Db2 up to 11.5.9/12.1.4. Impacted is an unknown function of the component JDBC. The manipulation results in os command injection.
This vulnerability is known as CVE-2026-9762. It is possible to launch the attack remotely. No exploit is available.
GHSA
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
ghsa_unreviewed·2026-07-17
CVE-2026-9762 [HIGH] CWE-94 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-17
Published