---
id: CVE-2026-81669
title: >-
  IBM Guardium Data Protection 12.2 is vulnerable to a command injection
  vulnerability in the create csr wildcard CLI command
summary: >-
  IBM Guardium Data Protection 12.2 is vulnerable to a command injection
  vulnerability in the create csr wildcard CLI command. An authenticated
  privileged CLI user can inject arbitrary shell commands through the alias
  input, resulting in c…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: IBM
product: Guardium Data Protection
affected:
  - guardium_data_protection 12.2
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:17:24.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81669'
references:
  - url: 'https://www.ibm.com/support/pages/node/7288040'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-18T19:49:30.591Z'
epss: 0.01322
epssPercentile: 0.69196
---

## Overview

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
