Junglewise Threat Intelligence

CVE-2026-84073: IBM Guardium Data Protection SQL injection

CVE-2026-84073 · Severity: critical · CVSS 9.1 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a security monitoring and audit tool that protects sensitive databases and applications. A vulnerability in version 12.2 allows authenticated users to inject malicious SQL commands, potentially exposing or modifying sensitive data stored in monitored databases. An attacker with legitimate access credentials could extract confidential information, alter audit records, or compromise the integrity of protected systems.

Technical details

CVE-2026-84073 is a SQL injection vulnerability in IBM Guardium Data Protection 12.2 arising from improper neutralization of special characters in SQL commands. The vulnerability requires network access and authenticated credentials, with no user interaction needed. An authenticated attacker can execute arbitrary SQL queries to read, modify, or delete data in the underlying database.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats