OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-85542

HIGH · CVSS 8.8 EPSS 2.41%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

IBM Guardium Data Protection 12.2 is vulnerable to a command injection flaw in its GIM bundle import feature, allowing authenticated attackers to execute arbitrary commands with elevated privileges on the Central Manager by supplying a specially crafted GIM bundle. This high-severity vulnerability poses significant risks to data integrity and system security. Organizations using this version of IBM Guardium should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-85542
Severity
HIGH
CVSS
8.8
EPSS
2.41%

Original NVD Description

IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated privileges on the Central Manager.