CVE-2026-84440: Command Injection
Published Sep 17, 2026
·Updated
IBM Security Guardium is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
Affected Software
1 affected component
IBM Guardium Data Protection<=12.2
Event History
Sep 17, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated attacker who can influence policy alert text can exploit the vulnerability. Systems using the SNMP alert notification functionality are the relevant exposure point.
2
What level of access could successful exploitation provide?
Attacker-controlled data can be executed as operating system commands by the SNMP alerter service. That service runs with root privileges, so command execution occurs with root-level privileges.