IBM has disclosed CVE-2026-75875, a critical path traversal vulnerability (CVSS 9.8) in IBM Guardium Data Protection 12.0, 12.1, and 12.2 that could let a remote attacker execute arbitrary code.
What Is It
CVE-2026-75875 is a path traversal weakness, classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). According to the NVD record, IBM Guardium Data Protection "could allow a remote attacker to execute arbitrary code due to path traversal."
IBM's PSIRT ([email protected]) reported the CVE. NVD published it on 2026-10-08, and its status is currently "Received," which means NVD has not yet completed its own analysis.
Why It Matters
IBM gave the flaw a CVSS v3.1 base score of 9.8 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That vector means:
- Network-exploitable: the attacker needs no local access
- Low attack complexity
- No privileges required: the attacker doesn't need to log in
- No user interaction required
- High impact to confidentiality, integrity, and availability
The exploitability subscore is 3.9 and the impact subscore is 5.9. An unauthenticated attacker who can reach the service over the network may be able to fully compromise an affected system.
Exploitation status: The supplied CISA KEV data has no entry for this CVE. As of this writing, KEV does not confirm active exploitation. Watch the KEV catalog for updates.
What's Vulnerable
The affected product is IBM Guardium Data Protection, in these versions:
| Version | Status |
|---|---|
| 12.0 (12.0.0) | Affected |
| 12.1 (12.1.0) | Affected |
| 12.2 (12.2.0) | Affected |
Associated CPEs:
- cpe:2.3:a:ibm:guardium_data_protection:12.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:guardium_data_protection:12.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Patch Status
The NVD record links to an IBM support advisory (node 7291674) but does not include fixed versions or patch details. Because there is no KEV entry, CISA has not set a required action or a remediation due date.
Organizations running Guardium Data Protection 12.0, 12.1, or 12.2 should:
- Read IBM's advisory for remediation guidance and any available fixes
- Rank this flaw as a high priority, given the unauthenticated network attack vector and critical severity