Summary
CVE-2026-84249 is a missing authentication for critical function vulnerability (CWE-306) in IBM Guardium Data Protection. A remote, unauthenticated attacker could execute arbitrary management operations on affected systems. The vulnerability is rated Critical (CVSS 9.8).
Technical details
- Root cause: Missing authentication for a critical function (CWE-306).
- Trigger conditions: No privileges and no user interaction are required; attack complexity is low.
- Attack vector: Network – remotely exploitable.
- Impact: A remote attacker could execute arbitrary management operations, with high impact on confidentiality, integrity and availability.
Affected software
- IBM Guardium Data Protection 12.2 (including 12.2.0)
- IBM Guardium Data Protection 12.2.2
Severity
- CVSS v3.1 base score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fixes IBM provides through IBM Fix Central. The IBM advisory lists
SqlGuard_12.0p233_FixPackfor 12.2 andSqlGuard_12.0p15004_Edgefor 12.2.2. Follow the IBM advisory for the exact fix applicable to your version. - Workarounds: IBM lists none. Until patched, restrict network access to Guardium management interfaces to trusted administrative networks only, and do not expose them to the internet.

