CVE-2026-84436

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-29: 209-29
Referenced assets1 URL
Full discourse2 posts
  • Xavier Rivera@XavierRiveraX

    IBM Guardium Data Protection 12.2 has a critical command injection in the certificate export CLI. CVE-2026-84436 scores 9.1. A privileged user can run root commands. Patch 12.2 now and restrict who can reach that CLI. Full writeup: https://thecircuitry.to/article/critical-command-injection-flaw-in-ibm-guardium-122-mun0lhh7

    0000043
    601 followersView on X
  • The Circuitry@thecircuitry_

    CVE-2026-84436 hits IBM Guardium 12.2 at 9.1 • Injection weakness in CLI certificate export • Privileged CLI access yields root commands NVD tags the entry critical. https://thecircuitry.to/article/critical-command-injection-flaw-in-ibm-guardium-122-mun0lhh7 https://t.co/PJgfo8a4J6

    0000022
    37 followersView on X

Explore more