CVE-2026-11906
IBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated user
Description
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns.
INFO
Published Date :
June 30, 2026, 7:42 p.m.
Last Modified :
June 30, 2026, 7:42 p.m.
Remotely Exploit :
Yes !
Source :
ibm
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | MEDIUM | 9a959283-ebb5-44b6-b705-dcc2bbced522 |
Solution
- Update IBM Db2 to the latest version.
- Apply recommended security patches from IBM.
- Review and sanitize XMLTable query inputs.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-11906 vulnerability anywhere in the article.