Sensitive Information Exposure in IBM Guardium Data Protection
CVE-2026-84274

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
8 October 2026

What is CVE-2026-84274?

IBM Guardium Data Protection 12.2.2 has a vulnerability that allows sensitive credential material to be logged at the INFO level during the rotation of SECRET and API_KEY by its edge-controller/edge-manager components. This logging can be exploited by an authenticated attacker with access to the application or container logs, potentially allowing them to obtain sensitive credentials. Once compromised, these credentials could be used to impersonate services or gain unauthorized access to the Guardium control plane, exposing critical data to threats.

Affected Version(s)

Guardium Data Protection 12.2.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.