Multiple Vulnerabilities in IBM Guardium Key Lifecycle Manager
Summary
| CVE | CVE-2026-1726 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-23 00:16:44 UTC |
| Updated | 2026-06-11 14:16:26 UTC |
| Description | IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthorized users to perform administrative operations after being demoted. Attackers could access sensitive data, modify system configurations, or change permissions for other users. The issue undermines administrative controls and could lead to data breaches, system compromise, and loss of trust in the application's security mechanisms. |
Risk And Classification
Primary CVSS: v3.1 4.8 MEDIUM from ADP
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS: 0.001940000 probability, percentile 0.091970000 (date 2026-06-17)
Problem Types: CWE-269 | NVD-CWE-noinfo | CWE-269 CWE-269 Improper Privilege Management
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 4.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 4.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Guardium Key Lifecycle Manager | 4.1.0 | All | All | All |
| Application | Ibm | Guardium Key Lifecycle Manager | 4.1.1 | All | All | All |
| Application | Ibm | Guardium Key Lifecycle Manager | 4.2.0 | All | All | All |
| Application | Ibm | Guardium Key Lifecycle Manager | 4.2.1 | All | All | All |
| Application | Ibm | Guardium Key Lifecycle Manager | 5.0.0 | All | All | All |
| Application | Ibm | Guardium Key Lifecycle Manager | 5.1.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | IBM | Guardium Key Lifecycle Manager | affected 4.1.0 semver | Not specified |
| CNA | IBM | Guardium Key Lifecycle Manager | affected 4.1.1 semver | Not specified |
| CNA | IBM | Guardium Key Lifecycle Manager | affected 4.2.0 semver | Not specified |
| CNA | IBM | Guardium Key Lifecycle Manager | affected 4.2.1 semver | Not specified |
| CNA | IBM | Guardium Key Lifecycle Manager | affected 5.0.0 semver | Not specified |
| CNA | IBM | Guardium Key Lifecycle Manager | affected 5.1.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.ibm.com/support/pages/node/7268697 | [email protected] | www.ibm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: IBM encourages customers to update their systems promptly. Principal Product and Version(s)Remediation/FixesIBM Guardium Key Lifecycle Manager (GKLM) v4.1 1. Download IBM Guardium Key Lifecycle Manager https://www.ibm.com/docs/en/gklm/5.x?topic=software-download-instructions
There are currently no legacy QID mappings associated with this CVE.