Junglewise Threat Intelligence

CVE-2026-84071: IBM Guardium Data Protection OS command injection in Universal Connector plugin

CVE-2026-84071 · Severity: high · CVSS 7.2 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a database security appliance that monitors and protects sensitive data. A privileged authenticated attacker can upload a malicious file with a crafted filename to the Universal Connector plugin, allowing them to execute arbitrary commands with root-level privileges on the appliance, potentially compromising the entire database security monitoring infrastructure.

Technical details

This is an OS command injection vulnerability (CWE-78) in the Universal Connector plugin upload functionality. A privileged authenticated attacker can inject shell metacharacters into a filename parameter that is unsafely incorporated into a shell command executed by the application, resulting in arbitrary command execution with root privileges. The attack requires authentication and the user to have privileges to upload plugins.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats