No advisories yet.
Solution
The vulnerability has been resolved in IBM Informix versions 14.10.xC13W13 and 15.0.1.13. The fix can be found on IBM Fix Central under the Informix Server section.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7282827 |
|
Wed, 12 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 IBM Informix could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input. | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input. |
Wed, 12 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 IBM Informix could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input. | |
| Title | IBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code Execution | |
| First Time appeared |
Ibm
Ibm informix Dynamic Server |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:ibm:informix_dynamic_server:12.10.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:informix_dynamic_server:12.10:*:*:*:*:*:*:* cpe:2.3:a:ibm:informix_dynamic_server:14.10.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:informix_dynamic_server:14.10:*:*:*:*:*:*:* cpe:2.3:a:ibm:informix_dynamic_server:15.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:informix_dynamic_server:15.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm informix Dynamic Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-08-12T21:01:16.803Z
Reserved: 2026-06-27T02:18:22.491Z
Link: CVE-2026-13476
No data.
Status : Received
Published: 2026-08-12T21:17:35.510
Modified: 2026-08-12T22:17:14.337
Link: CVE-2026-13476
No data.
OpenCVE Enrichment
Updated: 2026-08-13T02:30:12Z