Junglewise Threat Intelligence

CVE-2026-80441: IBM Guardium Data Protection SQL injection in generateInsertQuery

CVE-2026-80441 · Severity: critical · CVSS 9.8 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a database security appliance that monitors and protects database activities. An unauthenticated attacker can inject malicious SQL commands through the change-tracker-data component, allowing them to access, modify, or destroy sensitive data or disrupt system availability.

Technical details

Second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql allows unauthenticated remote attackers to inject arbitrary SQL. The vulnerability requires network access to the affected component but no authentication or user interaction. Successful exploitation results in full compromise of database confidentiality, integrity, and availability.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats