{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-81626","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2026-08-27T08:51:26.094Z","datePublished":"2026-09-18T19:26:37.621Z","dateUpdated":"2026-09-18T19:44:18.081Z"},"containers":{"cna":{"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-09-18T19:26:37.621Z"},"title":"IBM Guardium Data Protection is affected by multiple vulnerabilities.","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","type":"CWE"}]}],"affected":[{"vendor":"IBM","product":"Guardium Data Protection","versions":[{"status":"affected","version":"12.2"}],"cpes":["cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*","cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.</p>"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7288040","tags":["vendor-advisory","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW","baseSeverity":"HIGH","baseScore":8.6,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"}}],"solutions":[{"lang":"en","value":"IBM encourages customers to update their systems promptly.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc","supportingMedia":[{"type":"text/html","base64":false,"value":"<div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><div><p>IBM encourages customers to update their systems promptly.</p></div></div></div></div></div></div></div><div><div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><div><table><tbody><tr><td><strong> Product</strong></td><td><strong>Versions</strong></td><td><strong> Fix</strong></td></tr><tr><td>IBM Guardium Data Protection</td><td>12.2</td><td><a href=\"https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&amp;product=ibm/Information+Management/InfoSphere+Guardium&amp;release=12.2&amp;platform=Linux&amp;function=fixId&amp;fixids=SqlGuard_12.0p233_FixPack&amp;includeSupersedes=0&amp;source=fc\" rel=\"nofollow\">https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&amp;product=ibm/Information+Management/InfoSphere+Guardium&amp;release=12.2&amp;platform=Linux&amp;function=fixId&amp;fixids=SqlGuard_12.0p233_FixPack&amp;includeSupersedes=0&amp;source=fc</a></td></tr></tbody></table></div></div></div><p></p>"}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-18T19:44:07.033503Z","id":"CVE-2026-81626","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-18T19:44:18.081Z"}}]}}