CVE-2026-84245: IBM Guardium Data Protection vulnerability
Published Sep 17, 2026
·Updated
IBM Security Guardium Data Protection is vulnerable to a local privilege escalation in the cpwrapper component. A low-privileged local user could exploit this vulnerability to gain root privileges and access or modify sensitive system files.
Affected Software
1 affected component
IBM Guardium Data Protection<=12.2
Event History
Sep 17, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Systems running IBM Security Guardium Data Protection are exposed if a low-privileged user can obtain local access to the appliance or host.
2
What does an attacker need to exploit it?
The attacker needs an existing low-privileged local user account or equivalent local access. The issue is in the cp_wrapper component and can be used to obtain root privileges.
3
What is the potential impact after exploitation?
An attacker could gain root-level privileges and then access or modify sensitive system files.