Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-80442 2026-09-18

CVE-2026-80442: Critical Command Injection in IBM Guardium Data Protection 12.2

"IBM disclosed a critical (CVSS 9.9) authenticated OS command injection flaw in the `exportCertificate` functionality of Guardium Data Protection 12.2, allowing a low-privileged attacker to run arbitrary commands on the…"

IBM disclosed a critical (CVSS 9.9) authenticated OS command injection flaw in the exportCertificate functionality of Guardium Data Protection 12.2, allowing a low-privileged attacker to run arbitrary commands on the appliance.

What Is It

CVE-2026-80442 is an OS command injection vulnerability (CWE-78) in IBM Guardium Data Protection 12.2. The flaw sits in the product's exportCertificate functionality, where attacker-controlled input reaches an operating system command. IBM's PSIRT describes successful exploitation as allowing an attacker to execute unauthorized commands, impacting the confidentiality, integrity, and availability of the affected system.

The CVE was published on 2026-09-18 and currently carries NVD status "Received," meaning the record is still awaiting full NVD analysis.

Why It Matters

IBM scored this 9.9 CRITICAL under CVSS 3.1, using vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

The combination that drives the score: the flaw is reachable over the network with low attack complexity, needs no user interaction, and requires only low privileges; any authenticated account with access to the certificate export function is enough. Critically, the scope is Changed, meaning the impact extends beyond the vulnerable component itself, and all three impact metrics are High. The exploitability subscore is 3.1 and the impact subscore is 6.0.

Guardium Data Protection is a database activity monitoring and data security platform, so command execution on it lands on a system positioned with broad visibility into monitored data stores.

There is no CISA KEV entry for CVE-2026-80442 in the supplied data. Active exploitation is not confirmed by KEV at this time, and no required-action or KEV due date applies.

What's Vulnerable

No other versions are listed as affected in the supplied NVD record.

Patch Status

IBM has published a support advisory for this issue at node 7288040. The supplied NVD record lists that advisory as the sole reference and does not include specific fixed version numbers or interim mitigations; administrators running Guardium Data Protection 12.2 should consult the IBM advisory directly for remediation guidance.

Sources