CVE-2026-81933
published 2026-09-18CVE-2026-81933: IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can…
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.32%
24.8th percentile
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | guardium_data_protection | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Guardium Data Protection 12.2 Analytic Grid Service sql injection
vuldb·2026-09-18·CVSS 8.8
CVE-2026-81933 [HIGH] IBM Guardium Data Protection 12.2 Analytic Grid Service sql injection
A vulnerability has been found in IBM Guardium Data Protection 12.2 and classified as critical. This affects an unknown part of the component Analytic Grid Service Handler. Performing a manipulation results in sql injection.
This vulnerability is cataloged as CVE-2026-81933. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler.
ghsa_unreviewed·2026-09-18
CVE-2026-81933 [HIGH] CWE-89 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler.
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-18
Published