Junglewise Threat Intelligence

CVE-2026-84074: IBM Guardium Data Protection code execution via stored XSS

CVE-2026-84074 · Severity: high · CVSS 8.9 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a security tool that monitors and protects database activity for enterprises. A flaw in how the product sanitizes user input when generating web pages allows an authenticated attacker to inject malicious code that executes in other users' browsers, potentially leading to account takeover or system compromise. An attacker with valid credentials can craft inputs that persist in the application and execute arbitrary code when viewed by other users.

Technical details

CVE-2026-84074 is a stored cross-site scripting (XSS) vulnerability in IBM Guardium Data Protection 12.2, arising from improper neutralization of input during web page generation. An authenticated remote attacker can inject malicious script code that persists in the application and executes in the context of other users' sessions with the scope of the Guardium interface, enabling arbitrary actions within the application including code execution with the privileges of the affected user.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats