CVE-2026-81657

Published Sep 18, 2026

Last updated 3 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-81657 is a security vulnerability identified in IBM Guardium Data Protection version 12.2. This flaw stems from the improper handling of serialized objects, specifically the deserialization of untrusted data. The vulnerability allows a remote, unauthenticated attacker to execute arbitrary code on the affected system. This is achieved by injecting maliciously crafted input that triggers unsafe object reconstruction within the system's memory space, bypassing standard authentication mechanisms. The issue aligns with Common Weakness Enumeration (CWE) identifier CWE-502, which pertains to the deserialization of untrusted data.

Description
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Source
psirt@us.ibm.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@us.ibm.com
CWE-502

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

10

References

Sources include official advisories and independent security research.