IBM Guardium Data Protection: 25 Vulnerabilities Disclosed in Single Batch, Critical Flaws Threaten Code Execution
Key findings • 25 vulnerabilities in IBM Guardium Data Protection disclosed on October 8, 2026, ranging from Low to Critical severity. • Multiple critical vulnerabilities allow for remote cod…

Key findings
- 25 vulnerabilities in IBM Guardium Data Protection disclosed on October 8, 2026, ranging from Low to Critical severity.
- Multiple critical vulnerabilities allow for remote code execution, SQL injection, and authentication bypass.
- Path traversal and stored XSS vulnerabilities also present significant risks to data integrity and user sessions.
- Affected versions include IBM Guardium Data Protection 12.0, 12.1, 12.2, and 12.2.2.
- IBM has released patches; users are urged to apply updates promptly to mitigate risks.
On October 8, 2026, IBM disclosed a significant batch of 25 vulnerabilities affecting multiple versions of its Guardium Data Protection (GDP) product. The vulnerabilities, disclosed within a two-hour window, range in severity from Low to Critical, with a notable cluster of high and critical severity flaws impacting remote code execution, SQL injection, and authentication bypass. This coordinated disclosure event highlights potential risks for organizations relying on GDP for sensitive data security and compliance.
Several vulnerabilities center on the ability for remote attackers to execute arbitrary code. CVE-2026-84875, CVE-2026-84246, CVE-2026-84198, and CVE-2026-82895 are all described as buffer overflow vulnerabilities, with CVE-2026-84035 specifically noting a stack-based buffer overflow. CVE-2026-84057 presents a risk of arbitrary command execution due to improper neutralization of OS commands. Additionally, CVE-2026-84271, a critical vulnerability in the edge-controller component, allows unauthenticated remote attackers to execute arbitrary container images, potentially gaining control of managed edge clusters. CVE-2026-84272, also affecting the edge-controller, involves missing authentication for critical functions, enabling remote attackers to execute arbitrary management operations.
SQL injection remains a significant threat within this batch. CVE-2026-84209 allows remote attackers to execute arbitrary SQL commands due to improper neutralization of special elements in SQL commands. CVE-2026-81932, a high-severity SQL injection vulnerability, could permit an unauthenticated remote attacker to view, add, modify, or delete information in the back-end database. Furthermore, CVE-2026-80381, a critical SQL injection flaw, could allow remote attackers to execute unauthorized SQL statements.
Other critical vulnerabilities include CVE-2026-84244, a stored cross-site scripting (XSS) vulnerability in the Quick Search results grid, which could allow an unauthenticated attacker to execute malicious scripts in the browser of an authenticated Guardium user. CVE-2026-84249, another critical flaw, involves missing authentication for critical functions, allowing remote attackers to execute arbitrary management operations. Path traversal vulnerabilities also pose a risk, with CVE-2026-84275 allowing unauthenticated attackers to write arbitrary files to the Collector, and CVE-2026-75875 enabling remote attackers to execute arbitrary code. CVE-2026-84247, a path traversal vulnerability, could lead to a denial of service.
The batch also includes vulnerabilities related to information exposure and credential management. CVE-2026-87980, a low-severity issue, involves cleartext storage of sensitive information in logs. CVE-2026-84891, a medium-severity vulnerability, stems from the use of hard-coded credentials, potentially allowing remote attackers to obtain sensitive information. CVE-2026-84274, a medium-severity vulnerability, involves sensitive credential material being logged at the INFO level during secret and API key rotation. Local privilege escalation is also a concern, with CVE-2026-84245 allowing local attackers to recover the root password due to weak cryptography and a hard-coded recovery key, and CVE-2026-84244 enabling low-privileged local users to gain root privileges.
IBM Guardium Data Protection versions 12.0, 12.1, 12.2, and 12.2.2 are affected by various vulnerabilities within this batch. Specific versions are called out for certain flaws, such as CVE-2026-84249 and CVE-2026-84271 affecting 12.2.2 and 12.1, and CVE-2026-84274 affecting 12.2.2. CVE-2026-84275 specifically mentions version 12.2. IBM has released patches and updates to address these vulnerabilities. Users are strongly advised to consult IBM's security advisories and apply the necessary updates to mitigate the risks associated with these numerous security flaws.
The sheer volume and severity of vulnerabilities disclosed in this single batch underscore the importance of timely patching and security reviews for IBM Guardium Data Protection deployments. Organizations should prioritize addressing the critical and high-severity vulnerabilities to prevent potential code execution, data breaches, and unauthorized access to sensitive information. Continuous monitoring and prompt application of security updates are crucial for maintaining the integrity and security of data protection environments.