Junglewise Threat Intelligence

CVE-2026-81656: IBM Guardium Data Protection SQL injection in Query Builder

CVE-2026-81656 · Severity: high · CVSS 8.8 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a database security appliance that monitors and protects sensitive data in databases. A low-privileged authenticated user can inject malicious SQL commands through the Query Builder REST endpoint, potentially allowing unauthorized access to data stored in monitored databases, with impacts to data confidentiality, integrity, and availability.

Technical details

SQL injection vulnerability in the newQueryBuilder REST endpoint allows an authenticated attacker with low privileges to inject arbitrary SQL statements. The vulnerability results from improper neutralization of special elements used in SQL commands. Successful exploitation grants unauthorized database access with full confidentiality, integrity, and availability impact.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats