CVE-2026-84436: Command Injection
Published Sep 17, 2026
·Updated
IBM Security Guardium Data Protection is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
Affected Software
1 affected component
IBM Guardium Data Protection<=12.2
Event History
Sep 17, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Who can exploit this vulnerability?
Exploitation requires a privileged, authenticated user with access to the CLI certificate export functionality.
2
What level of access could an attacker gain?
A successful exploit can allow arbitrary command execution with root privileges.