IBM Guardium Data Protection: Four Command Injection and File Deletion Flaws Disclosed Together
Key findings • Four vulnerabilities disclosed together for IBM Guardium Data Protection 12.2. • Three command injection flaws allow for arbitrary code execution with root privileges. • On…

Key findings
- Four vulnerabilities disclosed together for IBM Guardium Data Protection 12.2.
- Three command injection flaws allow for arbitrary code execution with root privileges.
- One path traversal vulnerability allows for arbitrary file deletion.
- All vulnerabilities require authentication, with some needing privileged CLI access.
- Critical and High severity ratings indicate significant security risks.
On September 29, 2026, a batch of four vulnerabilities was disclosed for IBM Guardium Data Protection version 12.2. The vulnerabilities, all disclosed simultaneously, include critical and high-severity flaws that could allow authenticated attackers to execute arbitrary commands with root privileges, delete arbitrary files, and impact system integrity.
The disclosed vulnerabilities are:
- Command Injection: Three of the CVEs involve command injection flaws. CVE-2026-84440 affects the SNMP alert notification functionality, allowing an attacker who can influence alert text to execute OS commands as root. CVE-2026-84436 impacts the certificate export CLI functionality, enabling a privileged CLI user to execute arbitrary commands as root. Similarly, CVE-2026-84422, also in the CLI, allows a privileged CLI user to execute arbitrary commands with root privileges during SMIME recipient deletion.
- Path Traversal and File Deletion: CVE-2026-84842, found in the Datasource REST component, is a path traversal vulnerability that allows an authenticated remote attacker to delete arbitrary files. This could lead to a denial of service or compromise system integrity.
All disclosed vulnerabilities affect IBM Guardium Data Protection version 12.2. IBM has released security advisories detailing these vulnerabilities and recommending users update to a patched version. Users are urged to apply the available patches to mitigate the risk of exploitation.
This coordinated disclosure highlights significant security weaknesses in version 12.2 of IBM Guardium Data Protection, particularly concerning command injection and file manipulation capabilities. The ability for authenticated users to gain root privileges or delete critical files underscores the importance of timely patching and robust access control for sensitive data protection systems.