Junglewise Threat Intelligence

CVE-2026-82887: IBM Guardium Data Protection OS command injection

CVE-2026-82887 · Severity: high · CVSS 8.8 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a security tool that monitors and protects sensitive databases. An authenticated attacker can execute arbitrary operating system commands with the privileges of the Guardium service, potentially gaining complete control of the protected database environment and accessing all monitored data.

Technical details

OS command injection vulnerability due to improper neutralization of special elements in an OS command allows remote authenticated attackers to execute arbitrary commands. The attack requires authentication and network access. Successful exploitation grants the attacker command execution privileges on the Guardium Data Protection system.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats