CVE-2026-14501 (GCVE-0-2026-14501)
Vulnerability from cvelistv5
Published
2026-07-17 19:55
Modified
2026-07-20 18:02
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-676 - Use of Potentially Dangerous Function
Summary
IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions.
References
| URL | Tags | ||||
|---|---|---|---|---|---|
|
|||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| IBM | Db2 Genius Hub |
Version: 1.1, 1.1.1, 1.1.2 cpe:2.3:a:ibm:db2_genius_hub:1.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:db2_genius_hub:1.1.0:*:*:*:*:*:*:* |
||
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-14501",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-20T18:00:02.694960Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-20T18:02:26.778Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:ibm:db2_genius_hub:1.1:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:db2_genius_hub:1.1.0:*:*:*:*:*:*:*"
],
"product": "Db2 Genius Hub",
"vendor": "IBM",
"versions": [
{
"status": "affected",
"version": "1.1, 1.1.1, 1.1.2"
}
]
},
{
"cpes": [
"cpe:2.3:a:ibm:agentics:1.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:agentics:1.0.0:*:*:*:*:*:*:*"
],
"product": "Agentics",
"vendor": "IBM",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions.\u003c/p\u003e"
}
],
"value": "IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-676",
"description": "CWE-676 Use of Potentially Dangerous Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-17T19:55:50.177Z",
"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"shortName": "ibm"
},
"references": [
{
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://www.ibm.com/support/pages/node/7279901"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM strongly recommends addressing the vulnerability now.\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eProduct\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eVersion impacted\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eRemediation\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eIBM Db2 Genius Hub \u0026amp; Agentics\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e1.1, 1.1.1, 1.1.2\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eUpgrade to: IBM Db2 Genius Hub 1.1.3\u003cbr/\u003e\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EOther%20software\u0026amp;product=ibm/Information+Management/IBM+Db2+Genius+Hub\u0026amp;release=1.1.3.0\u0026amp;platform=All\u0026amp;function=all\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EOther%20software\u0026amp;product=ibm/Information+Management/IBM+Db2+Genius+Hub\u0026amp;release=1.1.3.0\u0026amp;platform=All\u0026amp;function=all\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e"
}
],
"value": "IBM strongly recommends addressing the vulnerability now.ProductVersion impactedRemediationIBM Db2 Genius Hub \u0026amp; Agentics1.1, 1.1.1, 1.1.2Upgrade to: IBM Db2 Genius Hub 1.1.3https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EOther%20software\u0026amp;product=ibm/Information+Management/IBM+Db2+Genius+Hub\u0026amp;release=1.1.3.0\u0026amp;platform=All\u0026amp;function=all"
}
],
"title": "Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub",
"x_generator": {
"engine": "ibm-cvegen"
}
}
},
"cveMetadata": {
"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"assignerShortName": "ibm",
"cveId": "CVE-2026-14501",
"datePublished": "2026-07-17T19:55:50.177Z",
"dateReserved": "2026-07-02T18:00:48.051Z",
"dateUpdated": "2026-07-20T18:02:26.778Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-14501\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-07-20T18:00:02.694960Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-07-20T18:00:32.014Z\"}}], \"cna\": {\"title\": \"Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub\", \"metrics\": [{\"format\": \"CVSS\", \"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 4.3, \"attackVector\": \"NETWORK\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N\", \"integrityImpact\": \"LOW\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"NONE\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"NONE\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"cpes\": [\"cpe:2.3:a:ibm:db2_genius_hub:1.1:*:*:*:*:*:*:*\", \"cpe:2.3:a:ibm:db2_genius_hub:1.1.0:*:*:*:*:*:*:*\"], \"vendor\": \"IBM\", \"product\": \"Db2 Genius Hub\", \"versions\": [{\"status\": \"affected\", \"version\": \"1.1, 1.1.1, 1.1.2\"}]}, {\"cpes\": [\"cpe:2.3:a:ibm:agentics:1.0:*:*:*:*:*:*:*\", \"cpe:2.3:a:ibm:agentics:1.0.0:*:*:*:*:*:*:*\"], \"vendor\": \"IBM\", \"product\": \"Agentics\", \"versions\": [{\"status\": \"affected\", \"version\": \"1.0\"}]}], \"solutions\": [{\"lang\": \"en\", \"value\": \"IBM strongly recommends addressing the vulnerability now.ProductVersion impactedRemediationIBM Db2 Genius Hub \u0026amp; Agentics1.1, 1.1.1, 1.1.2Upgrade to: IBM Db2 Genius Hub 1.1.3https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EOther%20software\u0026amp;product=ibm/Information+Management/IBM+Db2+Genius+Hub\u0026amp;release=1.1.3.0\u0026amp;platform=All\u0026amp;function=all\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eIBM strongly recommends addressing the vulnerability now.\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eProduct\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eVersion impacted\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eRemediation\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eIBM Db2 Genius Hub \u0026amp; Agentics\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e1.1, 1.1.1, 1.1.2\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eUpgrade to: IBM Db2 Genius Hub 1.1.3\u003cbr/\u003e\u003cbr/\u003e\u003ca href=\\\"https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EOther%20software\u0026amp;product=ibm/Information+Management/IBM+Db2+Genius+Hub\u0026amp;release=1.1.3.0\u0026amp;platform=All\u0026amp;function=all\\\" rel=\\\"nofollow\\\"\u003ehttps://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EOther%20software\u0026amp;product=ibm/Information+Management/IBM+Db2+Genius+Hub\u0026amp;release=1.1.3.0\u0026amp;platform=All\u0026amp;function=all\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\", \"base64\": false}]}], \"references\": [{\"url\": \"https://www.ibm.com/support/pages/node/7279901\", \"tags\": [\"vendor-advisory\", \"patch\"]}], \"x_generator\": {\"engine\": \"ibm-cvegen\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eIBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions.\u003c/p\u003e\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-676\", \"description\": \"CWE-676 Use of Potentially Dangerous Function\"}]}], \"providerMetadata\": {\"orgId\": \"9a959283-ebb5-44b6-b705-dcc2bbced522\", \"shortName\": \"ibm\", \"dateUpdated\": \"2026-07-17T19:55:50.177Z\"}}}",
"cveMetadata": "{\"cveId\": \"CVE-2026-14501\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-07-20T18:02:26.778Z\", \"dateReserved\": \"2026-07-02T18:00:48.051Z\", \"assignerOrgId\": \"9a959283-ebb5-44b6-b705-dcc2bbced522\", \"datePublished\": \"2026-07-17T19:55:50.177Z\", \"assignerShortName\": \"ibm\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…