CVE-2026-84245: IBM Guardium Data Protection Privilege Escalation
IBM Guardium Data Protection 12.2 is vulnerable to a local privilege escalation in the cpwrapper component. A low-privileged local user could exploit this vulnerability to gain root privileges and access or modify sensitive system files.
Other sources
IBM Security Guardium Data Protection is vulnerable to a local privilege escalation in the cpwrapper component. A low-privileged local user could exploit this vulnerability to gain root privileges and access or modify sensitive system files.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Systems running IBM Security Guardium Data Protection are exposed if a low-privileged user can obtain local access to the appliance or host.
What does an attacker need to exploit it?
The attacker needs an existing low-privileged local user account or equivalent local access. The issue is in the cp_wrapper component and can be used to obtain root privileges.
What is the potential impact after exploitation?
An attacker could gain root-level privileges and then access or modify sensitive system files.