{"id":"CVE-2026-81933","published":"2026-09-18T20:17:24.250","lastModified":"2026-09-23T04:17:50.807","description":"IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288040","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows a low-privileged authenticated user to inject SQL statements, potentially leading to unauthorized data access and system impact.","exploitability":"Exploitation requires low privileges and access to the analytic cases grid endpoint; the vulnerability is relatively easy to exploit given the low privilege requirement.","blast_radius":"If exploited, the vulnerability could result in unauthorized access to sensitive data, impacting confidentiality, integrity, and availability of the system.","remediation":"Upgrade to IBM Guardium Data Protection 12.2 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["sql-injection","auth-bypass","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:22:05.178Z"}}