IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthorized users to perform administrative operations after being demoted. Attackers could access sensitive data, modify system configurations, or change permissions for other users. The issue undermines administrative controls and could lead to data breaches, system compromise, and loss of trust in the application's security mechanisms.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7268697 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
11 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthorized users to perform administrative operations after being demoted. Attackers could access sensitive data, modify system configurations, or change permissions for other users. The issue undermines administrative controls and could lead to data breaches, system compromise, and loss of trust in the application's security mechanisms. |
27 Apr 2026, 18:21
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ibm
Ibm guardium Key Lifecycle Manager |
|
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:ibm:guardium_key_lifecycle_manager:4.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:guardium_key_lifecycle_manager:4.2.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:guardium_key_lifecycle_manager:4.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:guardium_key_lifecycle_manager:4.1.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:guardium_key_lifecycle_manager:5.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:guardium_key_lifecycle_manager:5.1.0:*:*:*:*:*:*:* |
|
| References | () https://www.ibm.com/support/pages/node/7268697 - Patch, Vendor Advisory |
23 Apr 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
23 Apr 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-23 00:16
Updated : 2026-06-11 14:16
NVD link : CVE-2026-1726
Mitre link : CVE-2026-1726
CVE.ORG link : CVE-2026-1726
JSON object : View
Products Affected
ibm
- guardium_key_lifecycle_manager
CWE
