Summary
CVE-2026-82900 is a path traversal vulnerability (CWE-22) in IBM Guardium Data Protection that could allow a remote attacker to delete arbitrary files. It affects versions 12.2.2 and 12.1 and carries a CVSS v3.1 base score of 8.1 (High).
Technical details
- Root cause: improper limitation of a pathname to a restricted directory (CWE-22).
- Trigger conditions: the attack requires no privileges and no user interaction; attack complexity is rated High.
- Attack vector: network, remote attacker.
- Impact: deletion of arbitrary files on the affected system. The CVSS vector rates confidentiality, integrity and availability impact as High.
Affected software
- IBM Guardium Data Protection 12.2.2 (Edge component)
- IBM Guardium Data Protection 12.1 (Guardium appliance), including 12.1.0
Severity
- CVSS v3.1 base score: 8.1 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply the IBM-provided fixes, available through IBM Fix Central:
- Edge patch 12.0p15004 (SqlGuard_12.0p15004_Edge) for the 12.2.2 Edge component.
- Patch 12.0p147 (SqlGuard_12.0p147_FixPack) for the 12.1 appliance.
- IBM’s bulletin states that no workarounds exist. As a precaution, restrict network access to Guardium management and Edge interfaces to trusted networks until patching is complete.

