CVE-2026-84422

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.

  • Published Sep 29, 2026
  • CVSS 7.2 high
  • 0.7% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-84422 at the National Vulnerability Database