Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-84272: IBM Guardium Data Protection lets attacker run code
CVE-2026-84272 · published 3 days ago
Summary
The Guardium Data Protection software version 12.1 and 12.2.2 fails to verify who is connecting to its edge‑controller part. Because of this, someone on the network can send commands that start any container they want, potentially taking over the edge servers that Guardium manages. Apply the latest security patches from IBM as soon as possible and restrict network access to the edge‑controller to trusted systems only.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | guardium data protection | 12.2.2 |
| ibm | guardium_data_protection |
12.1 12.2.2 cpe:2.3:a:ibm:guardium_data_protection:12.1:*:*:*:*:*:*:* |
Original advisory text
IBM Guardium Data Protection Missing Authentication
IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary container images and gain control of managed edge clusters.
References
- https://www.ibm.com/support/pages/node/7288832 vendor-advisory patch
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published8 Oct 2026
Updated11 Oct 2026
First seen8 Oct 2026
Track software like this
Free during beta