OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-84083 (CVSS 7.8)

NVD · officialPublished Sep 18, 2026Risk 23/100EPSS 0.1%

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute arbitrary commands as root, resulting in full compromise of the Collector appliance.

CVSS
7.8
AV:LocalAC:LowPR:LowUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source