---
id: CVE-2026-80442
title: >-
  IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command
  injection vulnerability in the exportCertificate functionality
summary: >-
  IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command
  injection vulnerability in the exportCertificate functionality. Successful
  exploitation could allow an attacker to execute unauthorized commands and
  impact th…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: IBM
product: Guardium Data Protection
affected:
  - guardium_data_protection 12.2
published: '2026-09-18'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T04:17:48.027'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80442'
references:
  - url: 'https://www.ibm.com/support/pages/node/7288040'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
epss: 0.01
epssPercentile: 0.61257
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T00:00:00+00:00'
ingestedAt: '2026-09-18T19:49:30.593Z'
---

## Overview

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
