{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/informix/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-13361"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Informix"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","vulnerability","database-security"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Informix is affected by a critical remote code execution vulnerability (CVE-2026-13361) localized within the \u003ccode\u003esq_sgkprepare\u003c/code\u003e function of the \u003ccode\u003eoninit\u003c/code\u003e process. The vulnerability stems from an unchecked length field handling mechanism when processing inputs through the SQL interface. This flaw allows a remote attacker to trigger a buffer overflow condition, resulting in the execution of arbitrary code with the privileges of the Informix service process. Given that \u003ccode\u003eoninit\u003c/code\u003e typically runs with elevated system privileges, successful exploitation provides an attacker with significant control over the underlying database server. Organizations using IBM Informix should prioritize patching or implementing compensating controls at the network boundary to restrict access to the SQL interface until remediation is complete.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-13361 results in full remote code execution on the target IBM Informix server. An attacker gaining these privileges can exfiltrate sensitive database contents, modify records, or move laterally into the host environment, potentially compromising the entire database cluster.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security patches provided by IBM for the Informix product line immediately upon release.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the Informix SQL interface (default ports) to trusted management subnets using host-based or network firewalls to mitigate unauthenticated exploitation attempts.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering on the database server to prevent payloads from initiating secondary callback connections or downloading additional stages from the internet.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T20:52:11Z","date_published":"2026-08-12T20:52:11Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ibm-informix-rce/","summary":"A critical buffer-related vulnerability (CVE-2026-13361) in IBM Informix allows remote, unauthenticated attackers to achieve code execution via the SQL interface by exploiting an unchecked length field in the oninit process.","title":"Remote Code Execution in IBM Informix via sq_sgkprepare","url":"https://feed.craftedsignal.io/briefs/2026-08-ibm-informix-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Informix","version":"https://jsonfeed.org/version/1.1"}