CVE-2026-18104
📛 CVE Title
IBM Db2 Mirror for i is vulnerable to obtain sensitive information []
Description
IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- ibm
- CVSS severity
- LOW
- CVSS score
- 3.3 / 10
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N- Effective score
- 3.3 / 10 LOW source: CNA overview
- CWE(s)
-
CWE-327 - Reserved
- 2026-07-28
- Published
- 2026-09-24 14:11 UTC
- Last updated
- 2026-09-24 14:11 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/18xxx/CVE-2026-18104.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-24 14:17:12 UTC
- NVD last modified
- 2026-09-24 14:51:56 UTC
- NVD CVSS v3.1
- 3.3 / 10 LOW source: psirt@us.ibm.com
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 1.4 / 10
NVD / KEV / EPSS data refreshed 2026-09-25 04:38 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-85892 - Assigner
- ibm
- Published
- Sep 24, 2026, 2:11:44 PM
- Updated
- Sep 24, 2026, 2:11:44 PM
- EUVD base score (CVSS 3.1)
-
3.3 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - EUVD-reported EPSS
- 0.0000
- Vendors
- IBM
- Products
-
Db2 Mirror for i (7.4)Db2 Mirror for i (7.5)Db2 Mirror for i (7.6)
- Aliases
-
GHSA-83g4-pfwh-946g
ENISA description: IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| IBM | Db2 Mirror for i |
7.6 (affected),
7.5 (affected),
7.4 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- https://www.ibm.com/support/pages/node/7289246 vendor-advisorypatch
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://www.ibm.com/support/pages/node/7289246 psirt@us.ibm.com
Remediations (10)
-
web:aicybr.com
Applicability is CVE - and release-specific. Compare each instance's exact family, patch and hot- fix level with ServiceNow's current advisory before a maintenance window. Hosted and self-hosted remediation ServiceNow-hosted instances ServiceNow says it deployed the security update to hosted instances.
2026-09-25 10:47 UTC -
web:anonhaven.com
CVE Details CVE ID CVE-2026-18104 Published Date Sep 24, 2026 Vendor IBM Severity LOW CVSS v3.1 Score 3.3
2026-09-25 10:47 UTC -
web:cvetodo.com
CVE-2026-18104 is a CVSS 3.3 low-severity vulnerability in Db2 Mirror For I. Full technical analysis, mitigations , and exploit status — updated in real time.
2026-09-25 10:47 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-09-25 10:47 UTC -
web:support.microsoft.com
The September 8, 2026 update for Windows 10, version 1809 and Windows Server 2019 includes security and cumulative reliability improvements in .NET Framework 3.5 and 4.8. We recommend that you apply this update as part of your regular maintenance routines. Before you install this update, see the Prerequisites and Restart requirement sections. Summary Security Improvements CVE - 2026 -62886 - .NET ...
2026-09-25 10:47 UTC -
web:vulners.com
This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.
2026-09-25 10:47 UTC -
web:www.ibm.com
IBM Db2 Mirror for i is vulnerable to obtaining sensitive information [ CVE-2026-18104 ] as described in the vulnerability details section.
2026-09-25 10:47 UTC -
web:www.oracle.com
This Critical Patch Update contains 1448 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.
2026-09-25 10:47 UTC -
web:www.rapid7.com
CVE-2026-18104 : IBM Db2 Mirror for i: IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of…. View severity, references, and remediation details from Rapid7.
2026-09-25 10:47 UTC -
web:www.strix.ai
How severe is CVE-2026-18104 ? CVE-2026-18104 has a CVSS score of 3.3/10 (LOW severity). How do I fix CVE-2026-18104 ? Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
2026-09-25 10:47 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-18104.json.
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*"
],
"product": "Db2 Mirror for i",
"vendor": "IBM",
"versions": [
{
"status": "affected",
"version": "7.6"
},
{
"status": "affected",
"version": "7.5"
},
{
"status": "affected",
"version": "7.4"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.</p>"
}
],
"value": "IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "NONE",
"baseScore": 3.3,
"baseSeverity": "LOW",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-327",
"description": "CWE-327 Use of a Broken or Risky Cryptographic Algorithm",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:11:44.621Z",
"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"shortName": "ibm"
},
"references": [
{
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://www.ibm.com/support/pages/node/7289246"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<div><table><tbody><tr><td><p>IBM i Release</p></td><td><p>5770-DBM PTF Numbers</p></td><td><p>PTF Download Link</p></td></tr><tr><td><p>7.6</p></td><td>SJ11539</td><td><p><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11539\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11539</a></p></td></tr><tr><td><p>7.5</p></td><td><p>SJ11538</p></td><td><p><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11538\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11538</a></p></td></tr><tr><td><p>7.4</p></td><td><p>SJ11540</p></td><td><p><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11540\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11540</a></p></td></tr></tbody></table></div><p><a href=\"https://www.ibm.com/support/fixcentral\" rel=\"nofollow\">https://www.ibm.com/support/fixcentral</a></p>"
}
],
"value": "IBM i Release\n\n\n\n5770-DBM PTF Numbers\n\n\n\nPTF Download Link\n\n\n\n7.6\n\nSJ11539\n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11539 \n\n\n\n7.5\n\n\n\nSJ11538\n\n\n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11538 \n\n\n\n7.4\n\n\n\nSJ11540\n\n\n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11540 \n\n\n\n\n\n https://www.ibm.com/support/fixcentral"
}
],
"title": "IBM Db2 Mirror for i is vulnerable to obtain sensitive information []"
}
},
"cveMetadata": {
"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"assignerShortName": "ibm",
"cveId": "CVE-2026-18104",
"datePublished": "2026-09-24T14:11:44.621Z",
"dateReserved": "2026-07-28T17:42:28.005Z",
"dateUpdated": "2026-09-24T14:11:44.621Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}