Junglewise Threat Intelligence

CVE-2026-82896: IBM Guardium Data Protection path traversal

CVE-2026-82896 · Severity: high · CVSS 7.6 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a database security solution that monitors and controls access to sensitive data. An authenticated attacker can traverse directories on the system to read arbitrary files, potentially exposing sensitive configuration data, credentials, or other protected information.

Technical details

A path traversal vulnerability in IBM Guardium Data Protection 12.2 allows a remote authenticated attacker to traverse the filesystem and read arbitrary files. The vulnerability requires authentication but no user interaction, accessed over the network. An attacker can read sensitive files outside the intended restricted directory.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats