Junglewise Threat Intelligence

CVE-2026-84031: IBM Guardium Data Protection XSS in web page generation

CVE-2026-84031 · Severity: critical · CVSS 9 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a database security monitoring appliance used to protect sensitive data across enterprises. CVE-2026-84031 is a cross-site scripting vulnerability that allows an authenticated attacker to inject malicious scripts into web pages, potentially leading to session hijacking, credential theft, or unauthorized administrative actions against the system.

Technical details

This is a reflected or stored XSS vulnerability (CWE-79) in the web interface resulting from improper input neutralization during HTML generation. An authenticated user with network access can craft malicious input during a web request that executes arbitrary JavaScript in the context of another user's browser session, particularly affecting administrators due to the high CVSS scope change rating.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats