CVE-2026-80381 is a critical SQL injection flaw in IBM Guardium Data Protection 12.0, 12.1, and 12.2 that could let a remote attacker execute unauthorized SQL statements.
What Is It
CVE-2026-80381 is a SQL injection vulnerability (CWE-89) in IBM Guardium Data Protection. According to the NVD record, a remote attacker could use it to execute unauthorized SQL statements against affected versions.
IBM's Product Security Incident Response Team ([email protected]) assigned the CVE. NVD published it on 2026-10-08 with a status of "Received," which means NVD has not finished its own analysis yet.
Why It Matters
IBM rates the flaw 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Based on that vector:
- Attack vector: Network. It can be exploited remotely.
- Attack complexity: Low.
- Privileges required: None. The attacker does not need to log in.
- User interaction: None.
- Impact: High for confidentiality, integrity, and availability.
The exploitability subscore is 3.9 and the impact subscore is 5.9. An attacker can reach the flaw over the network without credentials, and it affects a product built to protect data, so defenders should treat it as a priority.
Exploitation status: CVE-2026-80381 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. KEV does not confirm active exploitation, and the supplied material gives no other evidence of attacks in the wild.
What's Vulnerable
| Vendor | Product | Affected Versions |
|---|---|---|
| IBM | Guardium Data Protection | 12.0 |
| IBM | Guardium Data Protection | 12.1 |
| IBM | Guardium Data Protection | 12.2 |
The CPE identifiers list both the short and the full version strings: 12.0 / 12.0.0, 12.1 / 12.1.0, and 12.2 / 12.2.0.
Patch Status
The NVD record does not list fixed versions, patch identifiers, or workarounds. IBM's advisory is the only reference in the record, at the IBM support page linked below. Administrators running Guardium Data Protection 12.0, 12.1, or 12.2 should check that advisory for remediation guidance and fixed releases, and should apply IBM's fixes as soon as they can.
Because the vulnerability is not in the KEV catalog, CISA has not issued a required action or due date for federal agencies.
Sources
- NVD: CVE-2026-80381
- IBM Security Bulletin (node 7291674)
- CISA Known Exploited Vulnerabilities Catalog (no entry for this CVE as of publication)