OS Command Injection Vulnerability in IBM Guardium Data Protection
CVE-2026-84085

8.1HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2026-84085?

An OS command injection vulnerability exists in IBM Guardium Data Protection 12.2, allowing unauthorized remote attackers to execute arbitrary system commands. This flaw arises from improper handling of special elements used in OS commands. Attackers can exploit this vulnerability to manipulate the underlying operating system, which could lead to unauthorized access or control over the affected system. Users of IBM Guardium Data Protection are advised to apply available patches to mitigate risks associated with this vulnerability.

Affected Version(s)

Guardium Data Protection 12.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.