CVE-2026-84078: IBM Guardium Data Protection
Critical severity, CVSS 9.9. EPSS: 0.5% chance of exploitation in the next 30 days.
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system.
Affected products
- IBM Guardium Data Protection: version 12.2 only
Published 2026-09-18. Last modified 2026-10-06.