A critical authentication bypass in IBM Guardium Data Protection 12.2 lets an unauthenticated remote attacker slip past IP-based access controls and reach the Guardium management interface.
What Is It
CVE-2026-82967 is an authentication bypass affecting IBM Guardium Data Protection 12.2. Per IBM's advisory, the flaw allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface. It is classified as CWE-306 (Missing Authentication for Critical Function).
IBM PSIRT assigned a CVSS 3.1 base score of 9.8 (Critical), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low attack complexity, no privileges, no user interaction, with high impact to confidentiality, integrity, and availability.
Why It Matters
Guardium Data Protection is a database activity monitoring and data security platform; its management interface is the control plane for that monitoring. The vector yields the maximum CVSS 3.1 exploitability subscore of 3.9, meaning there is no meaningful barrier between a remote attacker and the interface beyond network reachability. Because IP allowlisting is the control being bypassed, organizations relying on network-level restrictions as their primary compensating control should assume that control is not holding.
Note that IP-based access controls are frequently treated as a sufficient perimeter for management interfaces; this bug invalidates that assumption for affected deployments.
What's Vulnerable
- Vendor: IBM
- Product: Guardium Data Protection
- Affected version: 12.2, as stated in IBM's advisory
The CVE record is still in a pre-analysis state, so NVD has not yet published analyzed CPE applicability data for this CVE. The affected-version set above reflects the vendor advisory only; treat the scope as provisional and confirm against IBM's advisory rather than assuming that adjacent releases are unaffected.
Patch Status
The CVE record was published 2026-09-18 with a status of Received, meaning NVD analysis was not yet complete at the time of writing. IBM has published a support advisory (node 7288035) as the sole vendor reference; administrators should consult that advisory directly for fix availability and upgrade guidance.
CVE-2026-82967 is not listed in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-18, so there is no KEV-confirmed active exploitation and no BOD 22-01 remediation deadline associated with it at this time.
Sources
- IBM Support advisory; https://www.ibm.com/support/pages/node/7288035
- NVD, CVE-2026-82967, https://nvd.nist.gov/vuln/detail/CVE-2026-82967
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog