Junglewise Threat Intelligence

CVE-2026-84086: IBM Guardium Data Protection path traversal arbitrary code execution

CVE-2026-84086 · Severity: high · CVSS 7.2 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a data security platform that monitors and protects databases from unauthorized access. A high-privileged authenticated attacker can exploit improper pathname validation to execute arbitrary code on the server, potentially compromising the entire database protection infrastructure and the data it guards.

Technical details

CVE-2026-84086 is a path traversal vulnerability (CWE-22) in IBM Guardium Data Protection that allows remote authenticated attackers with high privileges to bypass pathname restrictions and execute arbitrary code. The vulnerability requires network access and high-privilege authentication; exploitation results in complete system compromise including confidentiality, integrity, and availability impact.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats