Command Injection Vulnerability in IBM Guardium Data Protection
CVE-2026-84440

7.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
29 September 2026

What is CVE-2026-84440?

IBM Guardium Data Protection 12.2 is susceptible to a command injection vulnerability within its SNMP alert notification feature. An authenticated attacker with the ability to manipulate policy alert text could execute malicious data as operating system commands, leveraging the SNMP alerter service that operates with root privileges. This vulnerability exposes the system to significant security risks, as it allows unauthorized command execution within the affected environment.

Affected Version(s)

Guardium Data Protection 12.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.