Junglewise Threat Intelligence

CVE-2026-82892: IBM Guardium Data Protection OS command injection

CVE-2026-82892 · Severity: high · CVSS 8.1 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a security tool that monitors and protects databases from unauthorized access and misuse. A remote attacker can execute arbitrary operating system commands on the server, potentially gaining full control of the system and accessing sensitive data stored in monitored databases.

Technical details

The vulnerability is an OS command injection flaw (CWE-78) in IBM Guardium Data Protection 12.2 caused by improper neutralization of special elements in OS commands. An attacker can exploit this over the network to execute arbitrary commands with the privileges of the Guardium service. A patch has been made available by IBM.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats