CVE-2026-13476
Last modified
CVE-2026-13476 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Informix Dynamic Server | >= 15.0, < 15.0.1.13 |
| Ibm | Informix Dynamic Server | 12.10 |
| Ibm | Informix Dynamic Server | 14.10 |
References
- https://www.ibm.com/support/pages/node/7282827Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-13476?
How severe is CVE-2026-13476?
How do I fix CVE-2026-13476?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13462PayRange Android app, version 7.0.7 and below, contains an S…7.5
- CVE-2026-13463IBM Cloud Pak System 2.3.5.0 could allow a local attacker to…7.5
- CVE-2026-13464The Kirki – Freeform Page Builder, Website Builder & Customi…5.3
- CVE-2026-13468The Visualizer – Tables & Charts Manager with Built-in AI Ge…7.5
- CVE-2026-13473IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.…9.8
- CVE-2026-13474Denial of service via malformed HTTP/2 requests in NetScaler…7.5
- CVE-2026-13477IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 …8.8
- CVE-2026-13478The Zephyr ext2 filesystem driver validates the on-disk bloc…5.5
- CVE-2026-13479The LoRaWAN application-layer clock-synchronization service …4.3
- CVE-2026-13480The LoRaWAN TS004 Fragmented Data Block Transport handler fr…3.1
- CVE-2026-13481The IEEE 1588 PTP management-message parser in subsys/net/li…5.4
- CVE-2026-13482A vulnerability was detected in skypilot-org skypilot up to …3.7
Are you affected by CVE-2026-13476?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
