CVE-2026-18567
Received Received - Intake

IBM Db2 Mirror for i Race Condition Information Disclosure

Vulnerability report for CVE-2026-18567, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: IBM Corporation

Description

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
ibm db2_mirror_for_i From 7.4 (inc) to 7.6 (inc)
ibm db2_mirror_for_i 7.4
ibm db2_mirror_for_i 7.5
ibm db2_mirror_for_i 7.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 have a race condition in a world-writable directory. This flaw involves a predictable Unix domain socket path, which a local attacker could exploit to obtain sensitive information.

Impact Analysis

A local attacker could exploit this to gain unauthorized access to information stored or processed by the affected IBM Db2 Mirror for i versions. This may lead to data leaks or further system compromise depending on the attacker's goals.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating compliance requirements such as GDPR or HIPAA. Organizations may face penalties or legal consequences if such breaches occur due to unpatched systems.

Mitigation Strategies

Apply the PTF fixes provided by IBM for IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 as soon as possible to address the race condition vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18567. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart