Junglewise Threat Intelligence

CVE-2026-84077: IBM Guardium Data Protection CSRF security bypass

CVE-2026-84077 · Severity: high · CVSS 8.1 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a database security and monitoring solution used to protect sensitive data in enterprise environments. A cross-site request forgery flaw allows an attacker to trick authenticated users into performing unintended actions, potentially enabling unauthorized modifications to security policies, user accounts, or monitored database settings without the user's knowledge.

Technical details

CVE-2026-84077 is a CSRF vulnerability (CWE-352) in IBM Guardium Data Protection 12.2 that requires user interaction (victims must click a malicious link while authenticated). The attack requires network access and no special privileges. An unauthenticated attacker can cause an authenticated admin or user to unknowingly execute commands that modify system configuration or security controls. A patch is available from IBM.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats