CVE-2026-84422: Command Injection
Published Sep 17, 2026
·Updated
IBM Security Guardium Data Protection is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
Affected Software
1 affected component
IBM Guardium Data Protection<=12.2
Event History
Sep 17, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires an authenticated CLI user with privileged access. The issue is in the certificate SMIME recipient deletion functionality.
2
What level of access could successful exploitation provide?
A successful attacker could execute arbitrary commands with root privileges.