---
id: CVE-2026-84422
title: >-
  IBM Guardium Data Protection 12.2 is vulnerable to command injection in the
  CLI certificate SMIME recipient deletion functionality, allowing an
  authenticated privileged CLI user to execute arbitrary commands with root
  privileges.
summary: >-
  IBM Guardium Data Protection 12.2 is vulnerable to command injection in the
  CLI certificate SMIME recipient deletion functionality, allowing an
  authenticated privileged CLI user to execute arbitrary commands with root
  privileges.
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: IBM
product: Guardium Data Protection
affected:
  - guardium_data_protection 12.2
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:17:26.670'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84422'
references:
  - url: 'https://www.ibm.com/support/pages/node/7288034'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-29T18:11:44.362669Z'
ingestedAt: '2026-09-29T18:42:35.821Z'
---

## Overview

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
