Junglewise Threat Intelligence

CVE-2026-81626: IBM Guardium Data Protection SQL injection in Load Balancer

CVE-2026-81626 · Severity: high · CVSS 8.6 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a database and application security monitoring solution used by enterprises to protect sensitive data. An unauthenticated attacker can inject malicious SQL commands through the Load Balancer component, potentially allowing unauthorized access to confidential data, modification of information, or disruption of the system.

Technical details

SQL injection vulnerability in the Load Balancer Servlet endpoint allows unauthenticated remote attackers to inject arbitrary SQL statements due to improper neutralization of user input. The vulnerability requires no authentication, user interaction, or special configuration and provides direct access to the underlying database with potential for data exfiltration, modification, and denial of service.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats