Sensitive Information Exposure in IBM Guardium Data Protection
CVE-2026-84274
6.5MEDIUM
What is CVE-2026-84274?
IBM Guardium Data Protection 12.2.2 has a vulnerability that allows sensitive credential material to be logged at the INFO level during the rotation of SECRET and API_KEY by its edge-controller/edge-manager components. This logging can be exploited by an authenticated attacker with access to the application or container logs, potentially allowing them to obtain sensitive credentials. Once compromised, these credentials could be used to impersonate services or gain unauthorized access to the Guardium control plane, exposing critical data to threats.
Affected Version(s)
Guardium Data Protection 12.2.2