Junglewise Threat Intelligence

CVE-2026-84076: IBM Guardium Data Protection improper authorization bypass

CVE-2026-84076 · Severity: high · CVSS 7.6 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a database security monitoring and protection tool used to safeguard sensitive data in enterprise databases. A remote authenticated attacker can bypass security restrictions due to improper authorization, potentially gaining unauthorized access to protected database systems and sensitive information. This allows an attacker to circumvent the access controls that should restrict who can perform certain operations.

Technical details

The vulnerability stems from improper authorization validation in Guardium Data Protection 12.2, allowing a remote authenticated attacker to bypass security restrictions. It requires network access and prior authentication to exploit. A successful attack enables privilege escalation or unauthorized access to restricted resources without admin-level credentials.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats