Skip to content
IBMCVE-2026-13476

IBM Informix Dynamic Server: remote code execution

High7.3CVE-2026-13476 · Published Aug 12, 2026 · updated Aug 18, 2026

IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.

IBM advisory

Affected versions

PackageAffectedFixed in
Informix Dynamic Server
Product
<= 14.10No fix yet
<= 15.0No fix yet
<= 12.10No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-78

More IBM advisories

All IBM
Advisory
IBM DataPower Gateway: race condition
Medium4.2Aug 12
IBM Db2: buffer overflow
High8.4Aug 12
IBM i: denial of service
High8.2Aug 12
IBM DOORS Next: improper authentication
Critical10.0Aug 12
IBM Db2: improper authorization
Medium4.3Aug 12
IBM i Access Client Solutions: code execution
High7.8Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.