Skip to content
CVE Alert: CVE-2026-15955 – IBM

CVE Alert: CVE-2026-15955 – IBM

Redpacketsecurity admin September 15, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.

This is a high-priority integrity risk for exposed database driver deployments; urgency cannot be elevated to emergency because KEV status, SSVC exploitation state, PoC availability and EPSS are not provided.

Successful exploitation could let an unauthenticated remote attacker alter files on the host, enabling service disruption, persistence, configuration tampering or preparation for further compromise. The principal business risk is corruption of database-supporting infrastructure and trusted application components, rather than direct data disclosure.

### Most likely attack path

The attack is network-based, requires low complexity, no existing privileges and no user interaction, making internet-facing or broadly reachable services particularly attractive. Scope is unchanged, so the immediate impact is expected on the vulnerable host; however, modified startup files, scripts, libraries or configuration could facilitate lateral movement through associated application and database credentials.

### Who is most exposed

Organisations running JDBC/SQLJ connectivity from shared application servers, middleware tiers, containers or externally reachable database services are most exposed. Risk increases where the driver runs with write access beyond its working directory or where database infrastructure is insufficiently segmented.

Alert on unexpected file creation or modification by database and application service accounts.

Monitor traversal-like path parameters and unusual driver-related requests.

Compare executable, library, startup-script and configuration hashes against approved baselines.

Investigate outbound connections or new processes following suspicious file-write activity.

### Mitigation and prioritisation

Apply IBM’s applicable security update or interim fix promptly; treat remediation as high priority.

Treat as priority 1 if KEV is confirmed or EPSS is at least 0.5.

Restrict driver-service write permissions to required directories and run under a dedicated least-privilege account.

Isolate database and middleware networks; limit inbound access to trusted application sources.

Test updates in representative clusters, then use staged change windows with rollback plans.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.