Executive brief
IBM Guardium Data Protection is a data security platform that monitors and protects databases from unauthorized access. A high-privileged authenticated attacker can exploit improper pathname validation to execute arbitrary code on the server, potentially compromising the entire database protection infrastructure and the data it guards.
Technical details
CVE-2026-84086 is a path traversal vulnerability (CWE-22) in IBM Guardium Data Protection that allows remote authenticated attackers with high privileges to bypass pathname restrictions and execute arbitrary code. The vulnerability requires network access and high-privilege authentication; exploitation results in complete system compromise including confidentiality, integrity, and availability impact.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed