rootpwn

critical · CVSS v3 8.8 · EPSS 0.00277

CVE-2026-82885

IBM Guardium Data Protection version 12.2 contains a missing authorization flaw in its REST API. A remote authenticated attacker can leverag

Overview

IBM Guardium Data Protection version 12.2 contains a missing authorization flaw in its REST API. A remote authenticated attacker can leverage this vulnerability to gain elevated privileges within the system. This matters because compromised database activity monitoring controls can expose sensitive data and administrative functions.

Description

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

Impact

This vulnerability impacts the confidentiality, integrity, and availability of the affected system by allowing unauthorized privilege escalation. Organizations relying on Guardium for database security and compliance monitoring are directly affected. An authenticated user can bypass intended role restrictions to perform administrative actions they should not access.

Remediation

Apply the official vendor-supplied patches or security updates provided by IBM for Guardium Data Protection 12.2. Review and audit user role assignments and REST API access logs for anomalous activity. Restrict network access to the management and API interfaces to trusted administrators only.

Risk context

Rated as critical with a CVSS v3 score of 8.8, this vulnerability poses a significant risk due to the potential for complete privilege escalation. The current EPSS score is relatively low at 0.00277, indicating active exploitation in the wild may not yet be widespread, but remediation should still be prioritized given the high severity.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
EPSS
0.00277

IBM Guardium Privilege Escalation REST API Missing Authorization Database Security

← All CVEs