CVE-2026-82885

8.8

IBM · Guardium Data Protection

IBM Guardium Data Protection 12.2 contains a missing authorization vulnerability in its REST API that allows a remote authenticated attacker to gain elevated privileges.

Executive summary

A critical privilege escalation vulnerability in IBM Guardium Data Protection 12.2 allows authenticated attackers to gain unauthorized elevated access, posing a severe risk to data security.

Vulnerability

This flaw is classified as a missing authorization issue (CWE-862) within the REST API, enabling an attacker with low-level authenticated access to bypass intended security controls and perform actions with elevated privileges.

Business impact

The ability for an authenticated user to escalate privileges creates a significant risk of unauthorized data access, modification, or destruction within the Guardium environment. Given the CVSS score of 8.8, this vulnerability is classified as High severity and could result in full administrative compromise of the database security platform, potentially leading to widespread regulatory non-compliance and loss of sensitive data.

Remediation

Immediate Action: Update to the provided fix pack version SqlGuard_12.0p233_FixPack as specified in the IBM support portal.

Proactive Monitoring: Review REST API access logs for unusual patterns, such as repeated calls to administrative endpoints by non-administrative user accounts.

Compensating Controls: Implement strict network segmentation and restrict access to the REST API to known, trusted management IP addresses to reduce the attack surface.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the high CVSS severity and the potential for complete administrative compromise, organizations must prioritize the application of the IBM security update. Administrators should verify their current deployment version and apply the identified fix pack immediately to prevent unauthorized privilege escalation and ensure the integrity of the Guardium Data Protection environment.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources