CVE-2026-14501 Details
Description
IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions.
A vulnerability in IBM Db2 Genius Hub versions 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or access sensitive information. This issue arises from the use of potentially dangerous functions without adequate restrictions, creating opportunities for exploitation.
Users are advised to upgrade to IBM Db2 Genius Hub version 1.1.3. For IBM Agentics, the same version upgrade applies. Instructions for downloading the patched version are available on the IBM Support Fix Central website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7279901 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-676 | Use of Potentially Dangerous Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm agentics | 1.0 |
CPE
Remediation
| |
| ibm db2 genius hub | >= 1.1, < 1.1.3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 17, 2026 | New CVE Received | [email protected] |