← All Advisories

CVE-2026-84436

Last refreshed2026-10-03

Status: NEW  |  Advisory ID: CVE-2026-84436

Key Details

CVECVE-2026-84436
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

What to Know

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-84436
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-84436
Vendor advisoryhttps://www.ibm.com/support/pages/node/7288040