Summary
CVE-2026-75875 is a path traversal vulnerability (CWE-22) in IBM Guardium Data Protection that could allow a remote attacker to execute arbitrary code. It affects versions 12.0, 12.1 and 12.2 and is rated Critical with a CVSS v3.1 base score of 9.8.
Technical details
- Root cause: improper limitation of a pathname to a restricted directory (path traversal, CWE-22).
- Trigger conditions: per the CVSS vector, no privileges and no user interaction are required, and attack complexity is low.
- Attack vector: network; a remote attacker can exploit the flaw.
- Impact: arbitrary code execution, with high impact to confidentiality, integrity and availability.
Affected software
- IBM Guardium Data Protection 12.0
- IBM Guardium Data Protection 12.1
- IBM Guardium Data Protection 12.2
Severity
- CVSS v3.1 base score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply the latest IBM Guardium Data Protection Sniffer patch, available through IBM Fix Central, as directed in IBM’s security bulletin.
- No workarounds are documented in the sources reviewed. Until patched, restrict network access to Guardium management interfaces to trusted hosts only.

