Privilege Escalation Vulnerability in IBM Db2
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 are susceptible to privilege escalation due to improper authorization when processing crafted SQL queries.
CVE search metadata
CVE search record: CVE-2026-10543. Severity: high. CVSS: 8.2. KEV: no. Product: Db2 (11.5.0-11.5.9), Db2 (12.1.0-12.1.5). Brief: Privilege Escalation Vulnerability in IBM Db2. Brief link: https://feed.craftedsignal.io/briefs/2026-08-ibm-db2-privilege-escalation/
What's new
- 1. added coverage for Db2 (11.5.0-11.5.9) +1 products Aug 12, 22:53 via nvd
IBM has disclosed a security vulnerability, tracked as CVE-2026-10543, affecting multiple versions of IBM Db2. The vulnerability is classified as an improper authorization flaw (CWE-285) that allows an unauthenticated attacker to achieve privilege escalation through the submission of a specially crafted SQL query. With a CVSS base score of 8.2, this vulnerability poses a significant risk as it allows unauthorized changes to data integrity and potential escalation of access rights without requiring prior authentication or user interaction. Affected versions include the 11.5.x branch (up to 11.5.9) and the 12.1.x branch (up to 12.1.5). Organizations running these database versions are at risk of unauthorized administrative-level operations if an attacker successfully submits a malicious query to the database interface.
Impact
Successful exploitation allows an attacker to bypass authorization controls, potentially leading to a complete compromise of data integrity within the database environment. This vulnerability affects enterprise sectors relying on IBM Db2 for mission-critical storage and transaction processing. Unauthorized privilege escalation can facilitate unauthorized data modification, exfiltration of sensitive information, or the creation of backdoors within the database instance.
Recommendation
Prioritize the identification and patching of all IBM Db2 instances running the affected versions 11.5.0-11.5.9 and 12.1.0-12.1.5. Reference the official IBM security bulletin provided in the references section to obtain the relevant fix packs or service updates. Given the nature of the exploit, implement strict ingress filtering at the network level to limit database access to known, trusted application servers and administrative workstations to mitigate the risk of unauthenticated query submission.
Immediate actions
Audit environment for IBM Db2 versions 11.5.0-11.5.9 and 12.1.0-12.1.5
Mitigations
Apply the latest available IBM Db2 fix packs or security patches
CVE-2026-10543