CVE-2026-84272: IBM Guardium Data Protection Missing Authentication
IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary container images and gain control of managed edge clusters.
Other sources
IBM Security Guardium Data Protection is vulnerable to missing authentication in the edge-controller component. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary container images and gain control of managed edge clusters.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protection Edgeto a version that resolves this vulnerability.Fixed in 12.0p15004Patch SqlGuard_12.0p15004_Edge - Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Fixed in 12.0p147Patch SqlGuard_12.0p147_FixPack
Event History
Frequently Asked Questions
Which deployments are exposed?
IBM Guardium Data Protection versions 12.1 and 12.2.2 are identified as vulnerable, specifically through the edge-controller component. Deployments managing edge clusters are the relevant exposure scope.
Does exploitation require credentials or user interaction?
No. The vulnerability can be exploited remotely by an unauthenticated attacker, with no user interaction indicated.
What could an attacker do after exploiting this issue?
An attacker could execute arbitrary container images and gain control of managed edge clusters.