OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-80441

CRITICAL · CVSS 9.8 EPSS 0.56%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

IBM Guardium Data Protection 12.2 is susceptible to a critical unauthenticated second-order SQL injection vulnerability in the generateInsertQuery function, allowing remote attackers to execute malicious SQL commands. This could lead to severe impacts on the confidentiality, integrity, and availability of the system. Organizations using this version of Guardium should prioritize immediate remediation to mitigate potential exploitation risks.

CVE
CVE-2026-80441
Severity
CRITICAL
CVSS
9.8
EPSS
0.56%

Original NVD Description

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.

Related CVEs

Other vulnerabilities affecting the same vendor(s)