CRITICAL 9.8 NVD
CVE-2026-80441
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of chang
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.
References
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-18 via NVD.
Risk Timeline
CVE Disclosed2026-09-18 · -1 days ago
Remediation Resources
Analysis & PoC
www.ibm.com/support/pages/node/7288040
vulnfeed aggregates 14357 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.