IBMCVE-2026-84440
IBM Guardium Data Protection: command injection
High7.5CVE-2026-84440 · Published Sep 29, 2026 · updated Oct 1, 2026
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Guardium Data Protection Product | <= 12.2 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | IBM Guardium Data Protection: path traversal | High8.1 | No fix yet |
| Sep 29 | IBM i: insecure permissions | High7.8 | No fix yet |
| Sep 29 | IBM DataStage on Cloud Pak for Data: remote code execution | High8.8 | No fix yet |
| Sep 29 | IBM Guardium Data Protection: command injection | High7.2 | No fix yet |
| Sep 29 | IBM Guardium Data Protection: command injection | Critical9.1 | No fix yet |
| Sep 25 | IBM Guardium Data Protection: unsafe deserialization | High7.2 | No fix yet |