Weak Cryptographic Protection in IBM Guardium Data Protection
CVE-2026-84250

8.4HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
8 October 2026

What is CVE-2026-84250?

The IBM Guardium Data Protection 12.2 product is susceptible to a vulnerability stemming from inadequate cryptographic safeguards and the presence of a hard-coded recovery key within the pkcrypto passkey component. This weakness allows a local attacker to potentially recover the root password, thus granting them elevated root privileges and unauthorized access to sensitive data and system controls.

Affected Version(s)

Guardium Data Protection 12.2

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.