CVE-2026-84278: IBM Guardium Data Protection
High severity, CVSS 7.2. EPSS: 2.2% chance of exploitation in the next 30 days.
IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root ssh_config_wrapper component. An authenticated high-privileged user can inject arbitrary commands through attacker-controlled arguments, resulting in command execution with root privileges.
Affected products
- IBM Guardium Data Protection: version 12.2 only
Published 2026-10-08. Last modified 2026-10-10.