CVE-2026-84249 is a critical (CVSS 9.8) missing-authentication vulnerability in IBM Guardium Data Protection 12.2 and 12.2.2 that could let a remote attacker execute arbitrary management operations.
What Is It
CVE-2026-84249 is a missing-authentication-for-critical-function weakness (CWE-306) in IBM Guardium Data Protection. According to IBM's description in the NVD record, the flaw "could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function."
IBM PSIRT ([email protected]) submitted the record, and NVD published it on 2026-10-08. Its NVD status is currently "Received," which means NVD has not finished analyzing it.
Why It Matters
IBM rates the flaw 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. In practice, that means:
- Network-reachable: the attacker does not need local access.
- Low attack complexity: no special conditions are required.
- No privileges or user interaction required: the attacker does not need to log in or trick anyone.
- High impact on confidentiality, integrity and availability.
The affected function is management operations, so an unauthenticated attacker could perform administrative actions on the product without credentials.
Exploitation status: CVE-2026-84249 is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No active exploitation has been confirmed in the supplied data, and there is no KEV remediation deadline.
What's Vulnerable
| Vendor | Product | Affected Versions |
|---|---|---|
| IBM | Guardium Data Protection | 12.2, 12.2.2 |
The NVD record lists these CPEs:
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*cpe:2.3:a:ibm:guardium_data_protection:12.2.2:*:*:*:*:*:*:*
Patch Status
The supplied NVD data does not name fixed versions or describe a specific remediation. IBM links a support advisory from the record (see Sources). Administrators running Guardium Data Protection 12.2 or 12.2.2 should review that advisory for fix and mitigation guidance.
Because KEV does not list this CVE, there is no CISA-mandated required action. Given the CVSS score and the fact that no authentication is needed, organizations running affected versions should prioritize remediation.
Sources
- IBM Support Advisory (node 7288036)
- NVD: CVE-2026-84249
- CISA Known Exploited Vulnerabilities Catalog (not listed at time of writing)