Junglewise Threat Intelligence

CVE-2026-8405: IBM Guardium Data Protection credential disclosure in Long Term Retention

CVE-2026-8405 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection, a platform used for monitoring and securing sensitive databases, contains a vulnerability in its Long Term Retention (LTR) feature. When the system is placed in debug mode, it may inadvertently expose sensitive credentials to authenticated users. This could allow an internal user to gain unauthorized access to other parts of the data infrastructure, potentially leading to data theft or further system compromise.

Technical details

An information disclosure vulnerability (CWE-200) exists in the Long Term Retention (LTR) add-on of IBM Guardium Data Protection versions 12.2.1 and 12.2.2. The flaw occurs when the system is operating in debug mode, causing sensitive credentials to be written to logs or displayed in a manner accessible to authenticated users. An attacker with low-privileged network access could exploit this to obtain credentials, leading to a high impact on confidentiality. IBM has released security fixes for both affected versions to address this issue.

Affected products

  • IBM Guardium Data Protection 12.2.1, 12.2.2

Timeline

  • 2026-05-21: disclosed: Initial publication by IBM
  • 2026-05-21: patched: Fixes released via IBM Fix Central
  • 2026-05-27: advisory: NVD publication date

References

Related threats