Command Injection Vulnerability in IBM Guardium Data Protection
CVE-2026-84436

9.1CRITICAL

Key Information:

Vendor

IBM

Vendor
CVE Published:
29 September 2026

What is CVE-2026-84436?

IBM Guardium Data Protection version 12.2 is vulnerable to a command injection flaw found in its certificate export CLI functionality. This vulnerability allows a privileged authenticated CLI user to execute arbitrary commands with root privileges, potentially compromising system integrity and security. It is crucial for affected users to patch their systems to mitigate risks associated with unauthorized command execution.

Affected Version(s)

Guardium Data Protection 12.2

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.