OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-84071

HIGH · CVSS 7.2 EPSS 1.45%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

IBM Guardium Data Protection 12.2 is susceptible to OS command injection through the Universal Connector plugin's upload feature, allowing a privileged authenticated attacker to execute arbitrary commands with root-level privileges by supplying a malicious filename. This vulnerability poses a significant risk to the integrity and security of the system, making it critical for organizations using this version of Guardium to prioritize remediation efforts. Security teams should assess their environments and apply necessary updates or mitigations to safeguard against potential exploitation.

CVE
CVE-2026-84071
Severity
HIGH
CVSS
7.2
EPSS
1.45%

Original NVD Description

IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.

Related CVEs

Other vulnerabilities affecting the same vendor(s)