IBM Guardium Data Protection 12.2 contains a SQL injection flaw (CVSS 9.1) that, according to IBM, could allow a remote, authenticated attacker to execute arbitrary SQL commands against the platform.
What Is It
CVE-2026-84073 is an improper neutralization of special elements used in an SQL command (CWE-89) in IBM Guardium Data Protection 12.2. Per the vendor advisory, the product "could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command."
IBM PSIRT assigned a CVSS 3.1 base score of 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L. The vulnerability was published on 2026-09-18 and currently carries NVD status "Received," meaning NVD has not yet completed its own analysis; the severity and technical details below come from IBM's submission, not from independent NVD enrichment.
Why It Matters
The scoring tells the story: network attack vector, low attack complexity, no user interaction, and only low privileges required. The attacker needs some level of authenticated access, but nothing beyond a low-privilege account; a meaningful bar in practice, but a low one for anyone with credentials, a stolen session, or an existing foothold.
Two factors drive the score into critical territory. First, scope is changed (S:C), meaning successful exploitation affects resources beyond the vulnerable component's security authority. Second, confidentiality impact is HIGH, with integrity and availability rated LOW. Guardium Data Protection is a database security and activity-monitoring platform, so a confidentiality breach on the component itself is consequential by nature of what it holds.
What's Vulnerable
- Vendor: IBM
- Product: Guardium Data Protection
- Affected version: 12.2 (submitted CPE data covers
12.2and12.2.0)
This affected-version list comes from IBM's own advisory and CVE submission. Because the NVD record is still in "Received" status, NVD has not independently confirmed or expanded the affected-version configuration, and other versions could be added as analysis proceeds.
Patch Status
There is no entry for CVE-2026-84073 in the CISA Known Exploited Vulnerabilities catalog, and neither the IBM advisory nor the NVD record reports known exploitation as of publication. No required-action date or federal remediation deadline applies.
IBM has published a support advisory at node 7288040. No fixed version number appears in the public CVE or NVD record, so administrators running Guardium Data Protection 12.2 should consult the IBM advisory directly for remediation guidance and fix availability.
Sources
- IBM Support Advisory; https://www.ibm.com/support/pages/node/7288040
- NVD, CVE-2026-84073, https://nvd.nist.gov/vuln/detail/CVE-2026-84073
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog