PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-85029 IBM CVE debrief

IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory. This vulnerability exists in IBM Guardium Data Protection 12.2, which may be exposed to unauthorized access, file deletion, and code execution. Defenders should verify exposure and assess potential impact, especially in systems with remote access or exposed interfaces. The CVE record and NVD entry provide initial details, while IBM support pages may offer additional information on affected versions and remediation.

Vendor
IBM
Product
Guardium Data Protection
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-26
Advisory published
2026-09-25
Advisory updated
2026-09-26

Who should care

Defenders responsible for IBM Guardium Data Protection 12.2 systems, especially those with remote access or exposed interfaces, should assess potential exposure and impact.

Why it matters

Defenders should prioritize verifying exposure and assessing potential impact on systems using IBM Guardium Data Protection 12.2, especially those with remote access or exposed interfaces, due to the potential for unauthorized access, file deletion, and code execution.

  • Potential unauthorized access to sensitive information.
  • Possible deletion of arbitrary files.
  • Potential execution of arbitrary code.
  • Verification of exposure and impact is required.

Technical summary

The vulnerability exists due to improper limitation of a pathname to a restricted directory in IBM Guardium Data Protection 12.2. A remote attacker could exploit this vulnerability to obtain sensitive information, delete arbitrary files, or execute arbitrary code.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact on systems using IBM Guardium Data Protection 12.2, especially those with remote access or exposed interfaces.

Recommended defensive actions

  • Verify exposure of IBM Guardium Data Protection 12.2 systems, especially those with remote access or exposed interfaces.
  • Assess potential impact on systems and data.
  • Monitor for potential exploitation attempts.
  • Review IBM support pages for additional information on affected versions and remediation.

Evidence notes

The CVE record and NVD entry provide initial details on the vulnerability. IBM support pages may offer additional information on affected versions and remediation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-85029 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-85029

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-85029 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85029

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.