Authenticated OS Command Injection in IBM Guardium Data Protection
IBM Guardium Data Protection 12.2 contains an authenticated OS command injection vulnerability in the exportCertificate functionality that allows attackers to execute arbitrary system commands.
CVE search metadata
CVE search record: CVE-2026-80442. Severity: critical. CVSS: 9.9. KEV: no. Brief: Authenticated OS Command Injection in IBM Guardium Data Protection. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ibm-guardium-cve-2026-80442/
IBM Guardium Data Protection 12.2 contains a critical authenticated OS command injection vulnerability, tracked as CVE-2026-80442. The flaw resides in the exportCertificate functionality, which fails to properly sanitize user-supplied input before executing system commands. An attacker who has already achieved authenticated access to the application can leverage this vulnerability to execute arbitrary OS commands with the privileges of the underlying service. This allows for full system compromise, including the ability to exfiltrate sensitive database activity logs, modify monitoring configurations, or disrupt database operations managed by Guardium. Given the sensitive nature of the data protected by IBM Guardium, this vulnerability poses a severe risk to the confidentiality, integrity, and availability of the entire enterprise database infrastructure. Organizations should verify their current version and apply patches provided by IBM immediately.
Impact
Successful exploitation allows an authenticated attacker to execute unauthorized commands on the underlying host, leading to complete system compromise. Potential impacts include the exfiltration of protected database logs, disruption of security monitoring, and escalation of privileges within the management environment.
Recommendation
- Apply the security patch for CVE-2026-80442 provided by IBM to all instances of Guardium Data Protection 12.2.
- Review administrative access logs for the Guardium management console to identify unauthorized users or credential misuse.
- Monitor for unexpected process spawning from the web service