Junglewise Threat Intelligence

CVE-2026-82967: IBM Guardium Data Protection authentication bypass in IP-based access control

CVE-2026-82967 · Severity: critical · CVSS 9.8 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a security tool that protects databases and sensitive data by monitoring and controlling access to them. An unauthenticated attacker can bypass the IP-based access controls protecting the Guardium management interface, gaining unauthorized access to the system's administrative functions and potentially exposing or manipulating sensitive database monitoring data.

Technical details

The vulnerability is an authentication bypass affecting IP-based access controls in the Guardium management interface, exploitable remotely without authentication. This allows an unauthenticated attacker to access the administrative interface, potentially leading to full compromise of database monitoring and access control mechanisms. No preconditions such as user interaction or special network positioning are required.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats