Remote Code Execution Vulnerability in IBM Guardium Data Protection
CVE-2026-82890

5.9MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2026-82890?

A vulnerability in IBM Guardium Data Protection 12.2 allows remote authenticated users to execute arbitrary JavaScript code. This issue arises due to improper handling of user input during web page rendering, potentially leading to unauthorized access and manipulation of sensitive data. Organizations using this product should promptly assess their systems and implement the necessary security updates to mitigate the risk of exploitation.

Affected Version(s)

Guardium Data Protection 12.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.