CVE-2026-81669: IBM Guardium Data Protection is affected by multiple vulnerabilities.
Published Sep 17, 2026
·Updated
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges.
Affected Software
3 affected components
IBM Guardium Data Protection=12.2
IBM Guardium Data Protection<=12.2
IBM Guardium Data Protection<=12.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Patch SqlGuard_12.0p233_FixPack
Event History
Sep 17, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 18, 2026
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker needs access to the Guardium CLI as an authenticated privileged user. The vulnerable input is the alias parameter of the create csr wildcard CLI command.
2
What level of access could successful exploitation provide?
Successful exploitation can execute arbitrary shell commands with root privileges on the affected system.