CVE-2026-13361 PUBLISHED

IBM Informix Server Vulnerability in SQL Interface Handler Could Allow Remote Code Execution

Assigner: ibm
Reserved: 25.06.2026 Published: 12.08.2026 Updated: 13.08.2026

IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor IBM
Product Informix Dynamic Server
Versions
  • Version 14.10 is affected
  • Version 12.10.x is affected
  • Version 15.0 is affected

Solutions

The issue has been fixed in IBM Informix versions 14.10.xC13W13 and 15.0.1.14. Fixes are available on IBM Fix Central - Select Fixes - Informix Server. Follow the instructions for Database server upgrades in the Informix Servers documentation.

References

Problem Types

  • CWE-121 Stack-based Buffer Overflow CWE