CVE-2026-84078
published 2026-09-18CVE-2026-84078: IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access…
PriorityP267critical9.9CVSS 3.1
AVNACLPRNUINSCCLIHAL
EPSS
0.47%
38.4th percentile
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | guardium_data_protection | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Guardium Data Protection 12.2 LoadBalancerServlet missing authentication
vuldb·2026-09-18·CVSS 9.9
CVE-2026-84078 [CRITICAL] IBM Guardium Data Protection 12.2 LoadBalancerServlet missing authentication
A vulnerability classified as critical has been found in IBM Guardium Data Protection 12.2. The impacted element is the function LoadBalancerServlet. The manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2026-84078. The attack is possible to be carried out remotely. No exploit exists.
GHSA
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet.
ghsa_unreviewed·2026-09-18
CVE-2026-84078 [CRITICAL] CWE-306 IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet.
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-18
Published