CVE-2026-81656
published 2026-09-18CVE-2026-81656: IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.29%
22.3th percentile
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | guardium_data_protection | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor.
ghsa_unreviewed·2026-09-18
CVE-2026-81656 [HIGH] CWE-89 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor.
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.
VulDB
IBM Guardium Data Protection 12.2 New Query Builder sql injection
vuldb·2026-09-18·CVSS 8.8
CVE-2026-81656 [HIGH] IBM Guardium Data Protection 12.2 New Query Builder sql injection
A vulnerability was found in IBM Guardium Data Protection 12.2 and classified as critical. This vulnerability affects unknown code of the component New Query Builder. Executing a manipulation can lead to sql injection.
This vulnerability is registered as CVE-2026-81656. It is possible to launch the attack remotely. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-18
Published