IBMCVE-2026-81623
IBM Guardium Data Protection: code execution
Medium6.3CVE-2026-81623 · Published Sep 18, 2026 · updated Sep 23, 2026
IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation of user supplied input.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Guardium Data Protection Product | <= 12.2 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 18 | IBM Guardium Data Protection: improper authorization | High8.1 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: cross-site request forgery | High8.8 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: command injection | High8.1 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: remote code execution | High7.2 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: privilege escalation | High7.8 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: information disclosure | High7.7 | No fix yet |