Summary
CVE-2026-84057 is an OS command injection vulnerability (CWE-78) in IBM Guardium Data Protection. A remote attacker could execute arbitrary commands on affected systems. It is rated High severity (CVSS 8.1).
Technical details
- Root cause: improper neutralization of special elements used in an OS command (CWE-78).
- Trigger conditions: the CVSS vector indicates no privileges and no user interaction are required, but high attack complexity.
- Attack vector: network, remote.
- Impact: arbitrary command execution, with high impact on confidentiality, integrity and availability.
Affected software
- IBM Guardium Data Protection 12.2.2 (Edge component)
- IBM Guardium Data Protection 12.1 (Guardium appliance, listed as 12.1 and 12.1.0)
Severity
CVSS v3.1 base score 8.1 (High): CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply the IBM-provided patches from Fix Central: Edge patch
SqlGuard_12.0p15004_Edgefor the edge component (12.2 on Linux), andSqlGuard_12.0p147_FixPackfor the general appliance (all versions and platforms). - IBM states no workarounds are available, so patching is the only mitigation. Until patched, restrict network access to Guardium management interfaces to trusted networks where feasible.

