Junglewise Threat Intelligence

CVE-2026-84034: IBM Guardium Data Protection hardcoded credentials in hardware_assess/obstore

CVE-2026-84034 · Severity: high · CVSS 8.8 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a data security appliance that monitors and protects databases from unauthorized access and data theft. A low-privileged authenticated user can extract hardcoded credentials embedded in the hardware_assess and obstore binaries, gaining access to the system's master secrets and potentially compromising the internal database and sensitive information.

Technical details

The hardware_assess and obstore binaries in Guardium Data Protection 12.2 contain hardcoded credentials that can be recovered by a low-privileged authenticated user, leading to unauthorized access to product master secrets. This allows an attacker with basic authentication to escalate privileges and gain control over sensitive internal systems. The vulnerability requires prior authentication but no elevated privileges.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats