Junglewise Threat Intelligence

CVE-2026-84078: IBM Guardium Data Protection missing authentication in LoadBalancerServlet

CVE-2026-84078 · Severity: critical · CVSS 9.9 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a data security appliance that monitors and protects sensitive databases and files. An unauthenticated attacker can access privileged load-balancer operations without a password, potentially reconfiguring network traffic distribution, disrupting service availability, and compromising data integrity across protected systems.

Technical details

The LoadBalancerServlet component fails to enforce authentication checks before permitting load-balancer operations, allowing unauthenticated network access to privileged functions. An attacker can exploit this via the network to perform unauthorized administrative actions on the affected appliance, impacting both confidentiality and availability of monitored data systems.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats