CVE-2026-84278: Command Injection
Published Sep 17, 2026
·Updated
IBM Security Guardium Data Protection is affected by a command injection vulnerability in the SUID-root sshconfigwrapper component. An authenticated high-privileged user can inject arbitrary commands through attacker-controlled arguments, resulting in command execution with root privileges.
Affected Software
1 affected component
IBM Guardium Data Protection<=12.2
Event History
Sep 17, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Who can exploit this vulnerability?
Exploitation requires an authenticated, high-privileged user of IBM Guardium Data Protection. The vulnerable component is the SUID-root ssh_config_wrapper.
2
What level of access can successful exploitation provide?
An attacker who can inject commands through attacker-controlled arguments can execute arbitrary commands with root privileges.