CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-10109

Critical · CVSS 9.8

IBM Db2 — Remote Code Execution via improper pre-auth DRDA handshake handling (CWE-94 Code Injection)

CVSS
9.8
nvd
EPSS
0.86%
54th pct
KEV
No
Class
other
CWE-94

Description

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.

Search profile — drives PoC discovery

Symbols DRDAhandshakepre-authDb2DRDA handshake handlerRCEDRDA protocolIBM Db2 DRDA
Keywords CVE-2026-10109IBM Db2 RCEDb2 DRDA handshake vulnerabilityDb2 pre-auth remote code executionIBM Db2 11.5 exploitIBM Db2 12.1 exploitDb2 DRDA PoCCWE-94 IBM Db2IBM Db2 code injection
Versions: 11.5.0 through 11.5.9, 12.1.0 through 12.1.4

References

Status: enriched · ingested 2026-07-02T18:00:43.000Z · profiled 2026-07-02T18:30:43.000Z