← Back to search

CVE-2026-82967

9.8 CRITICAL

Published 2026-09-18 · Updated 2026-09-23

AI risk analysis

Summary
IBM Guardium Data Protection 12.2 allows unauthenticated attackers to bypass IP-based access controls and access the management interface, leading to unauthorized access.
Exploitability
Exploitation is relatively straightforward as it requires no user interaction and can be performed by any unauthenticated remote attacker.
Blast radius
If exploited, this vulnerability could lead to full control over the Guardium management interface, potentially compromising sensitive data and system integrity.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to IBM Guardium Data Protection 12.2.0.0 or later.
auth-bypasswebmanagement-interface

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-306

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.