{"id":"CVE-2026-84440","published":"2026-09-29T18:17:17.953","lastModified":"2026-09-30T04:18:33.167","description":"IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288035","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}