CVE-2026-1726

MEDIUM

IBM Guardium Key Lifecycle Manager 4.1-5.1 - Privilege Management Vulnerability

Title source: manual
STIX 2.1

Description

IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthorized users to perform administrative operations after being demoted. Attackers could access sensitive data, modify system configurations, or change permissions for other users. The issue undermines administrative controls and could lead to data breaches, system compromise, and loss of trust in the application's security mechanisms.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7268697

Scores

CVSS v3 4.8
EPSS 0.0019
EPSS Percentile 9.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (12)
IBM/Guardium Key Lifecycle Manager 4.1.0
IBM/Guardium Key Lifecycle Manager 4.1.1
IBM/Guardium Key Lifecycle Manager 4.2.0
IBM/Guardium Key Lifecycle Manager 4.2.1
IBM/Guardium Key Lifecycle Manager 5.0.0
IBM/Guardium Key Lifecycle Manager 5.1.0
ibm/guardium_key_lifecycle_manager 4.1.0
ibm/guardium_key_lifecycle_manager 4.1.1
ibm/guardium_key_lifecycle_manager 4.2.0
ibm/guardium_key_lifecycle_manager 4.2.1
... and 2 more
Published Apr 23, 2026
Tracked Since Apr 23, 2026