IBMCVE-2026-81933
IBM Guardium Data Protection: SQL injection
High8.8CVE-2026-81933 · Published Sep 18, 2026 · updated Sep 23, 2026
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Guardium Data Protection Product | <= 12.2 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-89
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 18 | IBM Guardium Data Protection: improper authorization | High8.1 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: cross-site request forgery | High8.8 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: command injection | High8.1 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: remote code execution | High7.2 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: privilege escalation | High7.8 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: information disclosure | High7.7 | No fix yet |