CVE-2026-81656: IBM Guardium Data Protection
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.
Affected products
- IBM Guardium Data Protection: version 12.2 only
Published 2026-09-18. Last modified 2026-10-06.