Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-84073 2026-09-18

CVE-2026-84073: Critical SQL Injection in IBM Guardium Data Protection 12.2

"IBM Guardium Data Protection 12.2 contains a SQL injection flaw (CVSS 9.1) that, according to IBM, could allow a remote, authenticated attacker to execute arbitrary SQL commands against the platform."

IBM Guardium Data Protection 12.2 contains a SQL injection flaw (CVSS 9.1) that, according to IBM, could allow a remote, authenticated attacker to execute arbitrary SQL commands against the platform.

What Is It

CVE-2026-84073 is an improper neutralization of special elements used in an SQL command (CWE-89) in IBM Guardium Data Protection 12.2. Per the vendor advisory, the product "could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command."

IBM PSIRT assigned a CVSS 3.1 base score of 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L. The vulnerability was published on 2026-09-18 and currently carries NVD status "Received," meaning NVD has not yet completed its own analysis; the severity and technical details below come from IBM's submission, not from independent NVD enrichment.

Why It Matters

The scoring tells the story: network attack vector, low attack complexity, no user interaction, and only low privileges required. The attacker needs some level of authenticated access, but nothing beyond a low-privilege account; a meaningful bar in practice, but a low one for anyone with credentials, a stolen session, or an existing foothold.

Two factors drive the score into critical territory. First, scope is changed (S:C), meaning successful exploitation affects resources beyond the vulnerable component's security authority. Second, confidentiality impact is HIGH, with integrity and availability rated LOW. Guardium Data Protection is a database security and activity-monitoring platform, so a confidentiality breach on the component itself is consequential by nature of what it holds.

What's Vulnerable

This affected-version list comes from IBM's own advisory and CVE submission. Because the NVD record is still in "Received" status, NVD has not independently confirmed or expanded the affected-version configuration, and other versions could be added as analysis proceeds.

Patch Status

There is no entry for CVE-2026-84073 in the CISA Known Exploited Vulnerabilities catalog, and neither the IBM advisory nor the NVD record reports known exploitation as of publication. No required-action date or federal remediation deadline applies.

IBM has published a support advisory at node 7288040. No fixed version number appears in the public CVE or NVD record, so administrators running Guardium Data Protection 12.2 should consult the IBM advisory directly for remediation guidance and fix availability.

Sources