Skip to content
IBMCVE-2026-84440

IBM Guardium Data Protection: command injection

High7.5CVE-2026-84440 · Published Sep 29, 2026 · updated Oct 1, 2026

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.

IBM advisory

Affected versions

PackageAffectedFixed in
Guardium Data Protection
Product
<= 12.2No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-78

More IBM advisories

All IBM
Advisory
IBM Guardium Data Protection: path traversal
High8.1Sep 29
IBM i: insecure permissions
High7.8Sep 29
IBM DataStage on Cloud Pak for Data: remote code execution
High8.8Sep 29
IBM Guardium Data Protection: command injection
High7.2Sep 29
IBM Guardium Data Protection: command injection
Critical9.1Sep 29
IBM Guardium Data Protection: unsafe deserialization
High7.2Sep 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.