← All Advisories

CVE-2026-84422

Last refreshed2026-10-03

Status: NEW  |  Advisory ID: CVE-2026-84422

Key Details

CVECVE-2026-84422
CVSS Score / Version7.2 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

What to Know

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-84422
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-84422
Vendor advisoryhttps://www.ibm.com/support/pages/node/7288034