CVE-2026-84250
Awaiting Analysis Awaiting Analysis - Queue

Weak Cryptographic Protection and Hard-Coded Recovery Key in IBM Guardium Data Protection

Vulnerability report for CVE-2026-84250, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: IBM Corporation

Description

IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
IBM Guardium Data Protection 12.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Guardium Data Protection 12.2 has a vulnerability caused by weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. This allows a local attacker to recover the root password and gain root privileges on the system.

Detection Guidance

To detect this vulnerability, check for the presence of the pkcrypto passkey component in IBM Guardium Data Protection 12.2. Verify if a hard-coded recovery key exists in the system. Inspect configuration files and logs for unusual root password recovery attempts or unauthorized privilege escalation.

Impact Analysis

An attacker could exploit this to gain full control of the system, access sensitive data, or perform unauthorized actions. This could lead to data breaches, system compromise, or disruption of services.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements such as GDPR or HIPAA. Organizations may face legal penalties, reputational damage, and loss of trust due to non-compliance.

Mitigation Strategies

Apply IBM's official patch or update for Guardium Data Protection 12.2 to address the weak cryptographic protection and hard-coded recovery key. Review and rotate all credentials, especially root passwords, that may have been exposed. Monitor systems for unauthorized access or privilege escalation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84250. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart