{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/informix-dynamic-server-14.10/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-13367"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Informix Dynamic Server (14.10)","Informix Dynamic Server (15.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","local-access"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM has identified a local privilege escalation vulnerability, tracked as CVE-2026-13367, affecting Informix Dynamic Server versions 14.10 and 15.0. The vulnerability resides within the 'oninit' utility, which is configured with the setuid-root bit. Due to improper access control (CWE-284), a low-privileged local attacker can exploit this utility to execute arbitrary code or commands with root privileges. This vulnerability poses a significant risk to the integrity and confidentiality of the host operating system, as it allows for a complete system compromise from a restricted user account. Defenders should prioritize patching or applying vendor-recommended mitigations to the 'oninit' utility binary.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes low-privileged access to the host server where IBM Informix is installed.\u003c/li\u003e\n\u003cli\u003eAttacker locates the 'oninit' utility, typically within the Informix binary directory, and confirms the setuid-root permission bit is active.\u003c/li\u003e\n\u003cli\u003eAttacker identifies inputs or environment variables that influence the execution flow of the 'oninit' process.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload or environment configuration to trigger the improper access control vulnerability.\u003c/li\u003e\n\u003cli\u003eAttacker executes the manipulated 'oninit' utility as a low-privileged user.\u003c/li\u003e\n\u003cli\u003eThe vulnerability in 'oninit' fails to drop privileges or improperly handles user input, leading to the execution of attacker-controlled commands with elevated root context.\u003c/li\u003e\n\u003cli\u003eAttacker successfully gains root-level command execution on the host system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local user to escalate privileges to root on the Informix host system. This may result in full system compromise, unauthorized access to sensitive database files, persistence via rootkit installation, or destruction of system-level configurations. IBM has confirmed the vulnerability impacts Informix Dynamic Server 14.10 and 15.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the official patch provided by IBM at \u003ca href=\"https://www.ibm.com/support/pages/node/7282829\"\u003ehttps://www.ibm.com/support/pages/node/7282829\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAudit file permissions on the 'oninit' binary to ensure only necessary users have execution rights.\u003c/li\u003e\n\u003cli\u003eEnable process monitoring on the 'oninit' binary to detect unusual executions or anomalous command-line arguments that may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T22:52:37Z","date_published":"2026-08-12T22:52:37Z","id":"https://feed.craftedsignal.io/briefs/2026-08-informix-lpe/","summary":"A local privilege escalation vulnerability in the oninit setuid-root utility of IBM Informix Dynamic Server 14.10 and 15.0 allows local authenticated users to gain elevated system privileges.","title":"Local Privilege Escalation in IBM Informix Dynamic Server","url":"https://feed.craftedsignal.io/briefs/2026-08-informix-lpe/"}],"language":"en","title":"CraftedSignal Threat Feed - Informix Dynamic Server (14.10)","version":"https://jsonfeed.org/version/1.1"}