high · CVSS v3 7.8
CVE-2026-84083
IBM Guardium Data Protection 12.2 contains a local privilege escalation vulnerability within the SUID-root nmap_wrapper binary on the Collec
Overview
IBM Guardium Data Protection 12.2 contains a local privilege escalation vulnerability within the SUID-root nmap_wrapper binary on the Collector appliance. Insufficient argument validation allows a low-privileged local user to execute arbitrary commands with root privileges, leading to full system compromise. This vulnerability is critical for environments where strict local access controls are necessary to maintain database security boundaries.
Description
IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute arbitrary commands as root, resulting in full compromise of the Collector appliance.
Impact
The vulnerability affects the confidentiality, integrity, and availability of the Guardium Collector appliance by allowing unprivileged local users to elevate their privileges to root. Successful exploitation grants complete administrative control over the affected appliance, potentially exposing sensitive database monitoring data. Organizations relying on Guardium Data Protection for compliance and security monitoring are directly impacted if local user hygiene is compromised.
Remediation
Apply the official vendor patch or security update provided by IBM for Guardium Data Protection 12.2. Restrict low-privileged shell access on Collector appliances and audit existing local user accounts to enforce the principle of least privilege. Monitor system logs for anomalous execution patterns involving the nmap_wrapper binary.
Risk context
The vulnerability carries a CVSS v3 score of 7.8, designating it as a high-severity issue due to the requirement for local access. While EPSS data is currently unavailable, defenders should treat local privilege escalation flaws with high urgency when unprivileged accounts exist on collector appliances.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 7.8
- CVSS v4
- —
- EPSS
- —