Summary
CVE-2026-80381 is a critical SQL injection vulnerability (CWE-89) in IBM Guardium Data Protection 12.0, 12.1 and 12.2. A remote attacker can execute unauthorized SQL statements. The CVSS v3.1 base score is 9.8 (Critical).
Technical details
- Root cause: improper neutralization of special elements used in an SQL command (CWE-89).
- Trigger conditions: none beyond network access. The vector requires no privileges and no user interaction, and attack complexity is low.
- Attack vector: network, remote.
- Impact: execution of unauthorized SQL statements, with high impact on confidentiality, integrity and availability.
- IBM’s bulletin lists the Sniffer component as impacted. This research did not find further details of the vulnerable endpoint or of exploitation.
Affected software
- IBM Guardium Data Protection 12.0
- IBM Guardium Data Protection 12.1
- IBM Guardium Data Protection 12.2
Severity
CVSS v3.1 base score 9.8 (Critical): CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply the latest Guardium Data Protection Sniffer patch from IBM Fix Central. The bulletin names
SqlGuard_12.0p4018_SnifferUpdate. It applies to versions 12.0, 12.1 and 12.2. - Workarounds: IBM documents none. As a precaution, restrict network access to Guardium management interfaces to trusted networks until the patch is applied.

