CVE-2026-84089
7.8IBM · Guardium Data Protection
IBM Guardium Data Protection 12.2 contains an improper privilege management vulnerability that permits a local attacker with low privileges to escalate their access to higher levels.
Executive summary
A local privilege escalation vulnerability in IBM Guardium Data Protection 12.2 could allow an authenticated attacker to gain unauthorized elevated system access.
Vulnerability
This vulnerability is caused by improper privilege management (CWE-269), allowing a locally authenticated user with low privileges to potentially achieve full administrative control over the affected system.
Business impact
The ability for a local user to escalate privileges poses a severe risk to the confidentiality, integrity, and availability of sensitive data managed by the platform. With a CVSS score of 7.8, this high-severity flaw could lead to complete system compromise, unauthorized data exfiltration, or the tampering of security audit logs.
Remediation
Immediate Action: Administrators must apply the provided security fix, identified as SqlGuard_12.0p233_FixPack, available via the IBM Fix Central portal.
Proactive Monitoring: Monitor system logs for unusual account activity, unexpected elevation of user sessions, or unauthorized modification of system configuration files.
Compensating Controls: Ensure that access to the underlying operating system is strictly restricted to authorized personnel only, adhering to the principle of least privilege to minimize the potential attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for total system compromise, this issue should be addressed with high urgency. Organizations running IBM Guardium Data Protection 12.2 must prioritize the deployment of the FixPack update to remediate the privilege management flaw and prevent potential local exploitation.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section