Executive brief
IBM Guardium Data Protection is a database security and compliance monitoring system used by enterprises to protect sensitive data. CVE-2026-84082 allows an unauthenticated remote attacker to execute arbitrary SQL commands against the database without any credentials or user interaction required. This could lead to complete compromise of the database, including theft or destruction of sensitive data stored within monitored systems.
Technical details
This is a SQL injection vulnerability (CWE-89) in IBM Guardium Data Protection 12.2 that fails to properly neutralize special elements used in SQL commands. The vulnerability is remotely exploitable without authentication (network vector, no privilege requirement, no user interaction), allowing an unauthenticated attacker to execute arbitrary SQL queries with full impact to confidentiality, integrity, and availability of the underlying database. A patch from IBM is available.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed