PatchSiren cyber security CVE debrief
CVE-2026-85029 IBM CVE debrief
IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory. This vulnerability exists in IBM Guardium Data Protection 12.2, which may be exposed to unauthorized access, file deletion, and code execution. Defenders should verify exposure and assess potential impact, especially in systems with remote access or exposed interfaces. The CVE record and NVD entry provide initial details, while IBM support pages may offer additional information on affected versions and remediation.
- Vendor
- IBM
- Product
- Guardium Data Protection
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-26
Who should care
Defenders responsible for IBM Guardium Data Protection 12.2 systems, especially those with remote access or exposed interfaces, should assess potential exposure and impact.
Why it matters
Defenders should prioritize verifying exposure and assessing potential impact on systems using IBM Guardium Data Protection 12.2, especially those with remote access or exposed interfaces, due to the potential for unauthorized access, file deletion, and code execution.
- Potential unauthorized access to sensitive information.
- Possible deletion of arbitrary files.
- Potential execution of arbitrary code.
- Verification of exposure and impact is required.
Technical summary
The vulnerability exists due to improper limitation of a pathname to a restricted directory in IBM Guardium Data Protection 12.2. A remote attacker could exploit this vulnerability to obtain sensitive information, delete arbitrary files, or execute arbitrary code.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact on systems using IBM Guardium Data Protection 12.2, especially those with remote access or exposed interfaces.
Recommended defensive actions
- Verify exposure of IBM Guardium Data Protection 12.2 systems, especially those with remote access or exposed interfaces.
- Assess potential impact on systems and data.
- Monitor for potential exploitation attempts.
- Review IBM support pages for additional information on affected versions and remediation.
Evidence notes
The CVE record and NVD entry provide initial details on the vulnerability. IBM support pages may offer additional information on affected versions and remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-85029 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-85029
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-85029 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85029
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7288034
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.