Junglewise Threat Intelligence

CVE-2026-84106: IBM Guardium Data Protection code execution via improper input neutralization

CVE-2026-84106 · Severity: high · CVSS 8.9 · Published 2026-09-18

Technologies: IBM Guardium Data Protection. Vendors: IBM.

Executive brief

IBM Guardium Data Protection is a data security and monitoring platform used to protect sensitive databases in enterprise environments. A vulnerability in web page generation could allow an authenticated remote attacker to execute arbitrary code on the system, potentially compromising the entire monitoring infrastructure and the databases it protects. This could lead to unauthorized access to sensitive data, system compromise, or denial of service.

Technical details

CVE-2026-84106 is a code injection vulnerability resulting from improper neutralization of input during web page generation, with elements of cross-site scripting (CWE-79). The vulnerability requires remote network access and authentication, plus user interaction to exploit. A successful attack would allow an authenticated attacker to execute arbitrary code with the privileges of the Guardium service, potentially achieving full system compromise.

Affected products

  • IBM Guardium Data Protection 12.2

Timeline

  • 2026-09-18: disclosed

References

Related threats