Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-80441 2026-09-18

CVE-2026-80441: Critical Unauthenticated SQL Injection in IBM Guardium Data Protection

"IBM Guardium Data Protection 12.2 contains a CVSS 9.8 unauthenticated second-order SQL injection flaw that a remote attacker can exploit to compromise the confidentiality, integrity, and availability of the affected…"

IBM Guardium Data Protection 12.2 contains a CVSS 9.8 unauthenticated second-order SQL injection flaw that a remote attacker can exploit to compromise the confidentiality, integrity, and availability of the affected system.

What Is It

CVE-2026-80441 is an unauthenticated second-order SQL injection vulnerability (CWE-89) in IBM Guardium Data Protection 12.2. A remote attacker can inject malicious SQL that the application subsequently processes, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.

Second-order means the injected payload is not executed at the point of submission; it is stored and later processed by the application, which makes the attack path harder to spot in request-level review.

Why It Matters

IBM's PSIRT assigned a CVSS 3.1 base score of 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Every exploitability dimension is maximally favorable to an attacker: network-reachable, low attack complexity, no privileges required, and no user interaction. The exploitability subscore is the maximum 3.9, with an impact subscore of 5.9 across all three CIA dimensions at HIGH.

Guardium Data Protection is a data security and activity monitoring platform, so the vulnerable component sits in the path of sensitive data.

CVE-2026-80441 does not appear in the CISA Known Exploited Vulnerabilities catalog as of this writing, so there is no confirmed active exploitation and no BOD 22-01 federal remediation due date on record. Absence from the KEV catalog reflects only what CISA has confirmed and dated; it is not evidence of safety, and the unauthenticated, no-interaction profile keeps this a priority regardless. Re-check the catalog directly, since entries are added as exploitation is confirmed.

What's Vulnerable

No other versions are listed as affected in the supplied record.

Patch Status

The CVE was published 2026-09-18 with a status of Received, meaning NVD analysis is not yet complete. The only vendor reference supplied is IBM Support node 7288040; consult that advisory for fix availability and remediation guidance. No required-action or due-date directive was supplied with this record.

Sources