Executive brief
IBM Guardium Key Lifecycle Manager, a solution used to manage encryption keys across an enterprise, contains a flaw that allows users to retain administrative powers even after their access has been revoked or demoted. An attacker with low-level access could exploit this to perform unauthorized administrative tasks, such as accessing sensitive encryption data or changing system security settings. This could lead to a significant data breach or a total compromise of the organization's key management infrastructure.
Technical details
IBM Guardium Key Lifecycle Manager (GKLM) versions 4.1 through 5.1 are vulnerable to improper privilege management (CWE-269). The flaw allows a user who has been demoted from an administrative role to continue executing administrative operations. An attacker with authenticated, low-privileged access can exploit this over the network, though the attack complexity is high. Successful exploitation enables the attacker to access sensitive data, modify system configurations, or alter permissions for other users. IBM has released a fix in version 5.1.0-ISS-GKLM-FP0001.
Affected products
- IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, 5.1
Timeline
- 2026-04-07: advisory: Initial publication by IBM
- 2026-04-23: disclosed: NVD publication date
- 2026-06-11: patched: Fix description updated in advisory