CVE-2026-13476 PUBLISHED

IBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code Execution

Assigner: ibm
Reserved: 27.06.2026 Published: 12.08.2026 Updated: 12.08.2026

IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 7.3

Product Status

Vendor IBM
Product Informix Dynamic Server
Versions
  • Version 14.10 is affected
  • Version 15.0 is affected
  • Version 12.10 is affected

Solutions

The vulnerability has been resolved in IBM Informix versions 14.10.xC13W13 and 15.0.1.13. The fix can be found on IBM Fix Central under the Informix Server section.

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE