Improper Pathname Limitation in IBM Guardium Data Protection
CVE-2026-85029

7.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
25 September 2026

What is CVE-2026-85029?

The IBM Guardium Data Protection software version 12.2 is vulnerable to a flaw that enables remote attackers to gain unauthorized access to sensitive information, delete arbitrary files, or execute arbitrary code. This vulnerability arises from an improper limitation of a pathname, allowing attackers to manipulate file operations beyond the expected confines. Organizations using this product should review their configurations and apply the necessary patches to mitigate the risk associated with this vulnerability.

Affected Version(s)

Guardium Data Protection 12.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.