← Back to search

CVE-2026-81657

9.8 CRITICAL

Published 2026-09-18 · Updated 2026-09-23

AI risk analysis

Summary
The flaw allows a remote unauthenticated attacker to execute arbitrary code on the system by deserializing untrusted data, posing a critical risk.
Exploitability
Exploitation is relatively straightforward with no preconditions other than network access to the affected IBM Guardium Data Protection 12.2 instance.
Blast radius
If exploited, this flaw could result in complete system compromise, leading to data loss, system corruption, and potential unauthorized access to sensitive information.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to IBM Guardium Data Protection 12.2.0.1 or later immediately.
rcearbitrary-code-executionunauthenticated

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.