Junglewise Threat Intelligence

CVE-2026-82885: IBM Guardium Data Protection missing authorization in REST API

CVE-2026-82885 · Severity: high · CVSS 8.8 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a database monitoring and compliance tool used to protect sensitive data in corporate environments. A vulnerability in its REST API could allow an authenticated user to gain elevated privileges and control system functions they should not have access to, potentially exposing or modifying protected data.

Technical details

A missing authorization check in the REST API allows an authenticated remote attacker to escalate privileges (CWE-862). The vulnerability requires authentication but no user interaction, accessible over the network. An attacker with basic authenticated access could perform administrative actions and access high-sensitivity data or modify system configuration.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats