Junglewise Threat Intelligence

CVE-2026-81623: IBM Guardium Data Protection command injection

CVE-2026-81623 · Severity: medium · CVSS 6.3 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a database security and auditing system that monitors sensitive data access. An authenticated user can inject arbitrary commands into the system due to insufficient input validation, potentially executing commands with elevated privileges and compromising the confidentiality, integrity, and availability of protected databases.

Technical details

OS command injection in Guardium Data Protection 12.2 via improper input validation allows an authenticated attacker to execute arbitrary commands with low user privileges. The vulnerability stems from insufficient sanitization of user-supplied input in command execution paths. An attacker with valid credentials can inject shell metacharacters to escalate command execution scope.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats