CVE-2026-84272 is a critical (CVSS 9.8) missing-authentication vulnerability in the edge-controller component of IBM Guardium Data Protection 12.1 and 12.2.2. A remote attacker can exploit it to run arbitrary container images and take control of managed edge clusters.
What Is It
The edge-controller component in IBM Guardium Data Protection does not require authentication for a critical function (CWE-306: Missing Authentication for Critical Function). IBM's description says an unauthenticated remote attacker could exploit this to run arbitrary container images and gain control of managed edge clusters.
IBM PSIRT ([email protected]) published the CVE on 2026-10-08. NVD lists it as "Awaiting Analysis."
Why It Matters
IBM assigned a CVSS v3.1 base score of 9.8 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That vector means:
- Network-reachable: the attacker only needs network access.
- Low attack complexity: no special conditions are required.
- No privileges or user interaction required
- High impact on confidentiality, integrity, and availability
Guardium Data Protection is a data security and monitoring platform, so an attacker who controls its edge clusters gains a strong foothold in a sensitive part of the environment. Running arbitrary container images gives the attacker code execution on the managed edge infrastructure.
This CVE does not currently appear in the CISA Known Exploited Vulnerabilities (KEV) catalog, so active exploitation is not confirmed. No KEV remediation deadline applies.
What's Vulnerable
According to the vendor-supplied NVD record, these versions are affected:
| Vendor | Product | Affected Versions |
|---|---|---|
| IBM | Guardium Data Protection | 12.1 (including 12.1.0) |
| IBM | Guardium Data Protection | 12.2.2 |
The vulnerable code is in the edge-controller component.
Patch Status
The NVD record links to an IBM support bulletin (node 7288832) as the vendor reference for this issue. The supplied data does not say which fixed versions, interim fixes, or workarounds are available. Administrators running Guardium Data Protection 12.1 or 12.2.2 should:
- Check the IBM bulletin for remediation guidance and apply the fixes it lists.
- Until a fix is applied, restrict network exposure of the edge-controller component.
Given the critical score and unauthenticated network attack vector, treat this as a priority patch even though exploitation has not been confirmed.
Sources
- NVD, CVE-2026-84272
- IBM Security Bulletin (node 7288832)
- CISA Known Exploited Vulnerabilities Catalog (CVE not listed at time of writing)