CVE-2026-81626

8.6

IBM · Guardium Data Protection

IBM Guardium Data Protection 12.2 contains a SQL injection vulnerability in the Load Balancer Groups component, allowing unauthenticated attackers to execute arbitrary SQL commands.

Executive summary

An unauthenticated SQL injection vulnerability in IBM Guardium Data Protection 12.2 poses a severe risk to data confidentiality and system integrity.

Vulnerability

This vulnerability is caused by improper neutralization of special elements in an SQL command within the Load Balancer Servlet endpoint. An unauthenticated attacker can leverage this flaw to inject malicious SQL statements, enabling unauthorized data access or disruption of services.

Business impact

Successful exploitation allows an attacker to bypass authentication and interact directly with the backend database. Given the CVSS score of 8.6, this vulnerability represents a high-severity risk that could lead to the exposure of sensitive database records, modification of data, or service degradation, potentially resulting in significant regulatory and operational consequences.

Remediation

Immediate Action: Apply the vendor-provided fix by installing the SqlGuard_12.0p233_FixPack available via the IBM Fix Central portal.

Proactive Monitoring: Review database audit logs for unusual query patterns, particularly those originating from the Load Balancer Servlet endpoint, and monitor for unexpected administrative activity.

Compensating Controls: Implement WAF rules to filter and block suspicious SQL syntax patterns directed at the application to mitigate risk until the patch can be deployed.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the high CVSS score and the absence of authentication requirements, this vulnerability should be prioritized for immediate remediation. Security teams must verify their Guardium deployment versions and apply the specified IBM fix pack as soon as possible to prevent potential unauthorized database access.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources