OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-81937

HIGH · CVSS 7.2 EPSS 1.45%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

IBM Guardium Data Protection 12.2 is susceptible to a command injection vulnerability that allows highly privileged authenticated users to execute arbitrary shell commands via the filename parameter in the import remotelog_config CLI command. This could lead to severe impacts on the confidentiality, integrity, and availability of the system, making it critical for organizations using this version of Guardium to prioritize remediation efforts. Security teams should focus on monitoring and patching this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-81937
Severity
HIGH
CVSS
7.2
EPSS
1.45%

Original NVD Description

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to the confidentiality, integrity, and availability of the affected system.

Related CVEs

Other vulnerabilities affecting the same vendor(s)