CVE-2026-84250: Weak Encryption
Published Sep 17, 2026
·Updated
IBM Security Guardium Data Protection is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.
Affected Software
1 affected component
IBM Guardium Data Protection<=12.2
Event History
Sep 17, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Does exploitation require local access to the affected system?
Yes. The vulnerability is described as exploitable by a local attacker; no remote attack path is identified in the available data.
2
Which component should be prioritized for investigation?
The issue is associated with the pkcrypto passkey component, which contains a hard-coded recovery key and weak cryptographic protection.