Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-84249 2026-10-08

IBM Guardium Data Protection Flaw Allows Unauthenticated Management Operations (CVE-2026-84249)

"CVE-2026-84249 is a critical (CVSS 9.8) missing-authentication vulnerability in IBM Guardium Data Protection 12.2 and 12.2.2 that could let a remote attacker execute arbitrary management operations."

CVE-2026-84249 is a critical (CVSS 9.8) missing-authentication vulnerability in IBM Guardium Data Protection 12.2 and 12.2.2 that could let a remote attacker execute arbitrary management operations.

What Is It

CVE-2026-84249 is a missing-authentication-for-critical-function weakness (CWE-306) in IBM Guardium Data Protection. According to IBM's description in the NVD record, the flaw "could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function."

IBM PSIRT ([email protected]) submitted the record, and NVD published it on 2026-10-08. Its NVD status is currently "Received," which means NVD has not finished analyzing it.

Why It Matters

IBM rates the flaw 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. In practice, that means:

The affected function is management operations, so an unauthenticated attacker could perform administrative actions on the product without credentials.

Exploitation status: CVE-2026-84249 is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No active exploitation has been confirmed in the supplied data, and there is no KEV remediation deadline.

What's Vulnerable

Vendor Product Affected Versions
IBM Guardium Data Protection 12.2, 12.2.2

The NVD record lists these CPEs:

Patch Status

The supplied NVD data does not name fixed versions or describe a specific remediation. IBM links a support advisory from the record (see Sources). Administrators running Guardium Data Protection 12.2 or 12.2.2 should review that advisory for fix and mitigation guidance.

Because KEV does not list this CVE, there is no CISA-mandated required action. Given the CVSS score and the fact that no authentication is needed, organizations running affected versions should prioritize remediation.

Sources