Junglewise Threat Intelligence

CVE-2026-84036: IBM Guardium Data Protection improper authorization bypass

CVE-2026-84036 · Severity: high · CVSS 7.4 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a database security and monitoring platform used by organizations to protect sensitive data and comply with regulations. A flaw in authorization checks allows authenticated users to bypass security restrictions and gain unauthorized access to data or functionality beyond their assigned permissions, potentially exposing sensitive information or enabling privilege escalation.

Technical details

The vulnerability is an improper authorization flaw (CWE-285) in IBM Guardium Data Protection that allows an authenticated remote attacker to bypass security restrictions. The attack requires valid authentication credentials and network access; no user interaction is needed. Exploitation enables an attacker to access or modify resources and functionality they should not have authorization for, with cross-system scope implications.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats