CVE-2026-82885
8.8IBM · Guardium Data Protection
IBM Guardium Data Protection 12.2 contains a missing authorization vulnerability in its REST API that allows a remote authenticated attacker to gain elevated privileges.
Executive summary
A critical privilege escalation vulnerability in IBM Guardium Data Protection 12.2 allows authenticated attackers to gain unauthorized elevated access, posing a severe risk to data security.
Vulnerability
This flaw is classified as a missing authorization issue (CWE-862) within the REST API, enabling an attacker with low-level authenticated access to bypass intended security controls and perform actions with elevated privileges.
Business impact
The ability for an authenticated user to escalate privileges creates a significant risk of unauthorized data access, modification, or destruction within the Guardium environment. Given the CVSS score of 8.8, this vulnerability is classified as High severity and could result in full administrative compromise of the database security platform, potentially leading to widespread regulatory non-compliance and loss of sensitive data.
Remediation
Immediate Action: Update to the provided fix pack version SqlGuard_12.0p233_FixPack as specified in the IBM support portal.
Proactive Monitoring: Review REST API access logs for unusual patterns, such as repeated calls to administrative endpoints by non-administrative user accounts.
Compensating Controls: Implement strict network segmentation and restrict access to the REST API to known, trusted management IP addresses to reduce the attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the high CVSS severity and the potential for complete administrative compromise, organizations must prioritize the application of the IBM security update. Administrators should verify their current deployment version and apply the identified fix pack immediately to prevent unauthorized privilege escalation and ensure the integrity of the Guardium Data Protection environment.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section