Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
CVE · Critical CVE-2026-84078 2026-09-18

IBM Guardium Data Protection 12.2: Unauthenticated Load Balancer Access (CVE-2026-84078)

"IBM Guardium Data Protection 12.2 exposes privileged load-balancer operations through an unauthenticated servlet, carrying a CNA-assigned CVSS 3.1 score of 9.9 (Critical)."

IBM Guardium Data Protection 12.2 exposes privileged load-balancer operations through an unauthenticated servlet, carrying a CNA-assigned CVSS 3.1 score of 9.9 (Critical).

What Is It

CVE-2026-84078 is a missing authentication vulnerability (CWE-306) in the LoadBalancerServlet component of IBM Guardium Data Protection 12.2. An unauthenticated user can reach privileged load-balancer operations directly, with no credentials and no user interaction required. IBM's PSIRT is the reporting source; the record was published 2026-09-18 and currently carries NVD status "Received." That status means the severity metrics and weakness classification below are as supplied by the CNA, NVD has not yet completed its own analysis, and the values may change when it does.

Why It Matters

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L, network-reachable, low attack complexity, no privileges, no user interaction, with a changed scope. That scope change is what pushes the base score to 9.9: the impact extends beyond the vulnerable servlet itself to other components of the affected system. Integrity impact is rated HIGH, with low confidentiality and availability impact, meaning the primary risk is unauthorized actions and manipulation rather than bulk data theft.

Guardium Data Protection is a database activity monitoring and compliance platform. Anything that lets an unauthenticated actor perform privileged operations against that infrastructure is a meaningful problem for the control plane that organizations rely on to watch their data stores.

What's Vulnerable

No other versions are listed as affected in the supplied record.

Patch Status

The supplied NVD record references a single IBM support advisory (node 7288040) as the authoritative vendor reference. No fixed version string, patch level, or workaround is included in the supplied data; administrators should consult the IBM advisory directly for remediation guidance.

The supplied record contains no information about exploitation status in the wild. Given the Critical severity and the trivial exploitation requirements, the absence of such information should not be read as evidence of low risk; treat remediation as time-sensitive and verify current exploitation and catalog status against CISA and vendor sources directly.

Sources