Answer in brief
CVE-2026-12628 records a Critical severity (CVSS 9.1) vulnerability in Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system. The current sources do not mark it as known exploited. The current feed maps IBM/Storage Protect Client (generic), IBM/Storage Protect Snapshot For Windows (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps IBM/Storage Protect Client (generic), IBM/Storage Protect Snapshot For Windows (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| IBM/Storage Protect Clientgeneric | 8.1.0.0 | Not reported |
| IBM/Storage Protect Snapshot For Windowsgeneric | 8.1.0.0 | Not reported |
Published upstream
Jun 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 22, 2026
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential embedded in multiple authentication code paths, and does not properly validate authentication responses, which may allow an unauthenticated attacker to establish a trusted session and access protected services. This vulnerability affects client components across multiple versions and may allow an attacker to impersonate legitimate clients, potentially leading to unauthorized access to system resources.
Quoted source text, attributed separately from HOL analysis.