{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-13476","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2026-06-27T02:18:22.491Z","datePublished":"2026-08-12T20:58:16.282Z","dateUpdated":"2026-08-14T22:16:24.859Z"},"containers":{"cna":{"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-08-12T21:01:16.803Z"},"title":"IBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code Execution","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-78","description":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","type":"CWE"}]}],"affected":[{"vendor":"IBM","product":"Informix Dynamic Server","versions":[{"status":"affected","version":"14.10"},{"status":"affected","version":"15.0"},{"status":"affected","version":"12.10"}],"cpes":["cpe:2.3:a:ibm:informix_dynamic_server:14.10:*:*:*:*:*:*:*","cpe:2.3:a:ibm:informix_dynamic_server:14.10.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:informix_dynamic_server:15.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:informix_dynamic_server:15.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:informix_dynamic_server:12.10:*:*:*:*:*:*:*","cpe:2.3:a:ibm:informix_dynamic_server:12.10.0:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.</p>"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7282827","tags":["vendor-advisory","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseSeverity":"HIGH","baseScore":7.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}}],"solutions":[{"lang":"en","value":"The vulnerability has been resolved in IBM Informix versions 14.10.xC13W13 and 15.0.1.13. The fix can be found on IBM Fix Central under the Informix Server section.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The vulnerability has been resolved in IBM Informix versions 14.10.xC13W13 and 15.0.1.13. The fix can be found on <a href=\"https://www.ibm.com/support/fixcentral/swg/selectFixes?function=all&amp;parent=ibm~Information%20Management&amp;platform=All&amp;product=ibm%2FInformation%20Management%2FInformix&amp;release=All&amp;mhsrc=ibmsearch_a&amp;mhq=Informix\" rel=\"noopener noreferrer nofollow\">IBM Fix Central under the Informix Server section</a>.</p>"}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-14T22:16:14.270959Z","id":"CVE-2026-13476","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-14T22:16:24.859Z"}}]}}