rootpwn

high · CVSS v3 7.8

CVE-2026-82893

IBM Guardium Data Protection 12.2 contains an improper privilege management vulnerability. This flaw allows a local user to escalate their p

Overview

IBM Guardium Data Protection 12.2 contains an improper privilege management vulnerability. This flaw allows a local user to escalate their privileges within the underlying operating environment. Addressing this issue is critical to maintaining strict access controls on database security appliances.

Description

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

Impact

An authenticated local attacker with low-level access can exploit this vulnerability to achieve elevated privileges on the affected system. This compromises the confidentiality, integrity, and availability of the Guardium appliance and potentially the sensitive database audit logs it manages. Database administrators and security teams relying on this platform are directly impacted.

Remediation

Apply the latest official security patches or fix packs provided by IBM for Guardium Data Protection 12.2. Restrict local shell access and strictly audit user accounts with access to the underlying operating system. Implement the principle of least privilege for all local users on database security appliances.

Risk context

Rated as a high severity vulnerability with a CVSS v3 score of 7.8, it presents a significant risk if local system access is compromised. EPSS data is currently not available for this CVE, but organizations should prioritize patching based on their local threat model and exposure to untrusted local users.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
high
CVSS v2
6.8
CVSS v3
7.8
CVSS v4
EPSS

IBM Guardium Privilege Escalation Local Access High Severity Access Control

← All CVEs