Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-84082 2026-09-18

IBM Guardium Data Protection 12.2 Hit by Critical SQL Injection Flaw (CVE-2026-84082)

"IBM has disclosed a critical, remotely exploitable SQL injection vulnerability in Guardium Data Protection 12.2 that carries a CVSS 3.1 base score of 9.8."

IBM has disclosed a critical, remotely exploitable SQL injection vulnerability in Guardium Data Protection 12.2 that carries a CVSS 3.1 base score of 9.8.

What Is It

CVE-2026-84082 is an SQL injection flaw (CWE-89) in IBM Guardium Data Protection 12.2. Per IBM's advisory, the product "could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command."

The CVSS vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, describes the worst-case profile for a network-facing product: attack over the network, low complexity, no privileges required, and no user interaction, with high impact to confidentiality, integrity, and availability. Exploitability scores 3.9 out of a possible 3.9.

Why It Matters

Per the CVSS metrics, an unauthenticated attacker reachable over the network could be able to run arbitrary SQL against the affected system. Guardium Data Protection is itself a data security and database activity monitoring platform, so the confidentiality, integrity, and availability impacts all rate HIGH, a successful compromise could reach the tooling organizations rely on to watch their databases.

CVE-2026-84082 does not currently appear in CISA's Known Exploited Vulnerabilities catalog, so active exploitation has not been confirmed by CISA at this time. The absence of a KEV listing is not evidence that exploitation is impossible; only that it has not been catalogued.

What's Vulnerable

No other versions are identified as affected in the NVD record.

Patch Status

The record was published on 2026-09-18 and currently carries NVD status Received, meaning the entry has not yet completed NVD analysis. The sole reference is IBM's support bulletin (node 7288040), which is the authoritative source for fix availability and remediation steps for this CVE. No CISA required action or due date applies, as the CVE is not listed in the KEV catalog.

Administrators running Guardium Data Protection 12.2 should consult the IBM bulletin directly for the vendor's remediation guidance.

Sources