{"id":"CVE-2026-82967","published":"2026-09-18T20:17:25.513","lastModified":"2026-09-23T04:17:54.210","description":"IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-306"],"vendors":[],"products":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288035","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"IBM Guardium Data Protection 12.2 allows unauthenticated attackers to bypass IP-based access controls and access the management interface, leading to unauthorized access.","exploitability":"Exploitation is relatively straightforward as it requires no user interaction and can be performed by any unauthenticated remote attacker.","blast_radius":"If exploited, this vulnerability could lead to full control over the Guardium management interface, potentially compromising sensitive data and system integrity.","remediation":"Upgrade to IBM Guardium Data Protection 12.2.0.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","web","management-interface"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T09:00:40.790Z"}}