Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-84272: IBM Guardium Data Protection lets attacker run code

CVE-2026-84272 · published 3 days ago
Summary

The Guardium Data Protection software version 12.1 and 12.2.2 fails to verify who is connecting to its edge‑controller part. Because of this, someone on the network can send commands that start any container they want, potentially taking over the edge servers that Guardium manages. Apply the latest security patches from IBM as soon as possible and restrict network access to the edge‑controller to trusted systems only.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm guardium data protection 12.2.2
ibm guardium_data_protection 12.1
12.2.2
cpe:2.3:a:ibm:guardium_data_protection:12.1:*:*:*:*:*:*:*
Original advisory text
IBM Guardium Data Protection Missing Authentication
IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary container images and gain control of managed edge clusters.
References
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published8 Oct 2026
Updated11 Oct 2026
First seen8 Oct 2026
Sources
CVE-2026-84272 · MITRE
Track software like this
Free during beta