← Back to search

CVE-2026-84078

9.9 CRITICAL

Published 2026-09-18 · Updated 2026-09-22

AI risk analysis

Summary
The flaw is a missing authentication vulnerability in IBM Guardium Data Protection 12.2's LoadBalancerServlet, allowing unauthenticated users to perform privileged operations, which could lead to unauthorized actions and impact system integrity and availability.
Exploitability
Exploitation is relatively easy as it requires no authentication, but the attacker must have network access to the LoadBalancerServlet.
Blast radius
If exploited, the impact could be significant, potentially leading to unauthorized access and manipulation of the system's operations and data.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to IBM Guardium Data Protection 12.2 or later.
auth-bypasswebprivileged-access

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

Weaknesses

CWE-306

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.