Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82967 2026-09-18

IBM Guardium Data Protection 12.2 Authentication Bypass (CVE-2026-82967)

"A critical authentication bypass in IBM Guardium Data Protection 12.2 lets an unauthenticated remote attacker slip past IP-based access controls and reach the Guardium management interface."

A critical authentication bypass in IBM Guardium Data Protection 12.2 lets an unauthenticated remote attacker slip past IP-based access controls and reach the Guardium management interface.

What Is It

CVE-2026-82967 is an authentication bypass affecting IBM Guardium Data Protection 12.2. Per IBM's advisory, the flaw allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface. It is classified as CWE-306 (Missing Authentication for Critical Function).

IBM PSIRT assigned a CVSS 3.1 base score of 9.8 (Critical), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low attack complexity, no privileges, no user interaction, with high impact to confidentiality, integrity, and availability.

Why It Matters

Guardium Data Protection is a database activity monitoring and data security platform; its management interface is the control plane for that monitoring. The vector yields the maximum CVSS 3.1 exploitability subscore of 3.9, meaning there is no meaningful barrier between a remote attacker and the interface beyond network reachability. Because IP allowlisting is the control being bypassed, organizations relying on network-level restrictions as their primary compensating control should assume that control is not holding.

Note that IP-based access controls are frequently treated as a sufficient perimeter for management interfaces; this bug invalidates that assumption for affected deployments.

What's Vulnerable

The CVE record is still in a pre-analysis state, so NVD has not yet published analyzed CPE applicability data for this CVE. The affected-version set above reflects the vendor advisory only; treat the scope as provisional and confirm against IBM's advisory rather than assuming that adjacent releases are unaffected.

Patch Status

The CVE record was published 2026-09-18 with a status of Received, meaning NVD analysis was not yet complete at the time of writing. IBM has published a support advisory (node 7288035) as the sole vendor reference; administrators should consult that advisory directly for fix availability and upgrade guidance.

CVE-2026-82967 is not listed in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-18, so there is no KEV-confirmed active exploitation and no BOD 22-01 remediation deadline associated with it at this time.

Sources