Junglewise Threat Intelligence

CVE-2026-82890: IBM Guardium Data Protection cross-site scripting in web page generation

CVE-2026-82890 · Severity: medium · CVSS 5.9 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a security monitoring system that protects databases from unauthorized access and threats. A remote authenticated attacker can inject malicious JavaScript code into web pages through improper input handling, allowing them to steal sensitive data or perform actions on behalf of other users when those users view the compromised page.

Technical details

The vulnerability is a cross-site scripting (CWE-79) flaw in web page generation that fails to neutralize user-supplied input. An authenticated remote attacker can inject arbitrary JavaScript which executes in the context of other users' browsers, enabling session hijacking, credential theft, or lateral movement within the management console. A fix has been released by IBM.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats