Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-84244 2026-10-08

Stored XSS in IBM Guardium Data Protection 12.2 Quick Search (CVE-2026-84244)

"IBM Guardium Data Protection 12.2 has a critical stored cross-site scripting flaw (CVE-2026-84244, CVSS 9.3). An unauthenticated attacker who can influence monitored database traffic could use it to run malicious script…"

IBM Guardium Data Protection 12.2 has a critical stored cross-site scripting flaw (CVE-2026-84244, CVSS 9.3). An unauthenticated attacker who can influence monitored database traffic could use it to run malicious script in an authenticated Guardium user's browser.

What Is It

CVE-2026-84244 is a stored cross-site scripting (XSS) vulnerability (CWE-79) in the Quick Search results grid of IBM Security Guardium Data Protection 12.2. IBM's PSIRT reported it, and it was published to NVD on 2026-10-08. NVD lists the record as "Awaiting Analysis."

The description says the attacker does not need to log in to Guardium. They only need to be able to influence the database traffic that Guardium monitors. Content injected that way is stored and then rendered in the Quick Search results grid. When an authenticated Guardium user views it, the script runs in that user's browser session.

Why It Matters

IBM rates the flaw 9.3 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N:

The scope is "Changed" and confidentiality impact is high. That means a successful attack reaches past the vulnerable component and into the session of the Guardium user viewing the data. Guardium watches database activity, so its users are usually security or database administration staff. The attack path also matters: the attacker plants the payload through the monitored data stream, not through the Guardium interface.

Exploitation status: This CVE is not in the CISA Known Exploited Vulnerabilities (KEV) catalog, and the supplied sources do not confirm any active exploitation. CISA's SSVC assessment as of 2026-10-08 lists exploitation as none, automatable as no and technical impact as partial.

What's Vulnerable

The affected component is the Quick Search results grid.

Patch Status

The NVD record does not list fixed versions or a specific remediation. Because the CVE is not in KEV, there is no CISA-mandated required action or due date. IBM has published a support page for the issue, linked below. Organizations running Guardium Data Protection 12.2 should read that advisory for fix and mitigation guidance and apply IBM's remediation as soon as possible, given the critical severity rating.

Sources