Junglewise Threat Intelligence

CVE-2026-81657: IBM Guardium Data Protection deserialization code execution

CVE-2026-81657 · Severity: critical · CVSS 9.8 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a security and compliance appliance that monitors and protects databases. A flaw in how the application processes untrusted data allows remote attackers without authentication to execute arbitrary code on the appliance, potentially compromising all monitored databases and the audit infrastructure.

Technical details

CVE-2026-81657 is an unauthenticated remote code execution vulnerability stemming from unsafe deserialization of untrusted data (CWE-502). The attack requires only network access and no authentication; a crafted malicious serialized object can trigger arbitrary code execution with full system privileges. No user interaction is required.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats