CVE-2026-84086
published 2026-09-18CVE-2026-84086: IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a…
PriorityP352high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.65%
49.8th percentile
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | guardium_data_protection | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Guardium Data Protection 12.2 path traversal
vuldb·2026-09-18·CVSS 7.2
CVE-2026-84086 [HIGH] IBM Guardium Data Protection 12.2 path traversal
A vulnerability was found in IBM Guardium Data Protection 12.2. It has been classified as very critical. The impacted element is an unknown function. This manipulation causes path traversal.
This vulnerability is registered as CVE-2026-84086. Remote exploitation of the attack is possible. No exploit is available.
GHSA
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
ghsa_unreviewed·2026-09-18
CVE-2026-84086 [HIGH] CWE-22 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-18
Published