Junglewise Threat Intelligence

CVE-2026-82832: IBM Guardium Data Protection code injection in web page generation

CVE-2026-82832 · Severity: critical · CVSS 9.6 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is database activity monitoring software that tracks and protects sensitive data access. A code injection vulnerability during web page generation allows an authenticated attacker to execute arbitrary code, potentially compromising the entire database security infrastructure and gaining access to monitored data.

Technical details

The vulnerability is a CWE-79 improper neutralization of input during web page generation (cross-site scripting). Exploitation requires remote network access and authenticated user credentials, with user interaction (UI:R). Successful exploitation enables arbitrary code execution on the application server with the privileges of the web service process.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats