CVE-2026-1726: IBM Guardium Key Lifecycle Manager

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthorized users to perform administrative operations after being demoted. Attackers could access sensitive data, modify system configurations, or change permissions for other users. The issue undermines administrative controls and could lead to data breaches, system compromise, and loss of trust in the application's security mechanisms.

Affected products

  • IBM Guardium Key Lifecycle Manager: version 4.1.0 only; version 4.1.1 only; version 4.2.0 only; version 4.2.1 only; version 5.0.0 only; version 5.1.0 only

Published 2026-04-23. Last modified 2026-06-17.