OS Command Injection in IBM Guardium Data Protection
CVE-2026-84071
7.2HIGH
What is CVE-2026-84071?
IBM Guardium Data Protection version 12.2 has a vulnerability that allows a malicious, authenticated user to exploit the Universal Connector plugin's upload functionality. By submitting a specially crafted filename, the attacker can execute arbitrary shell commands on the host system, which may lead to unauthorized access and control with elevated privileges. This security flaw emphasizes the importance of validating user inputs and safeguarding against injection attacks to maintain the integrity of system operations.
Affected Version(s)
Guardium Data Protection 12.2