CVE Vulnerabilities

CVE-2026-1726

Improper Privilege Management

Published: Apr 23, 2026 | Modified: Jun 11, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthorized users to perform administrative operations after being demoted. Attackers could access sensitive data, modify system configurations, or change permissions for other users. The issue undermines administrative controls and could lead to data breaches, system compromise, and loss of trust in the applications security mechanisms.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Guardium_key_lifecycle_managerIbm4.1.0 (including)4.1.0 (including)
Guardium_key_lifecycle_managerIbm4.1.1 (including)4.1.1 (including)
Guardium_key_lifecycle_managerIbm4.2.0 (including)4.2.0 (including)
Guardium_key_lifecycle_managerIbm4.2.1 (including)4.2.1 (including)
Guardium_key_lifecycle_managerIbm5.0.0 (including)5.0.0 (including)
Guardium_key_lifecycle_managerIbm5.1.0 (including)5.1.0 (including)

Potential Mitigations

References