PatchSiren cyber security CVE debrief
CVE-2026-80381 IBM CVE debrief
The Sniffer component in IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 contains multiple vulnerabilities that allow remote SQL injection attacks, potentially enabling attackers to execute unauthorized SQL statements. This could lead to data breaches or system compromise. Defenders responsible for IBM Guardium Data Protection deployments, particularly those using versions 12.0, 12.1, and 12.2, should assess exposure and prioritize patching or mitigation to prevent potential SQL injection attacks.
- Vendor
- IBM
- Product
- Guardium Data Protection
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for IBM Guardium Data Protection deployments, particularly those using versions 12.0, 12.1, and 12.2, should assess exposure and prioritize patching or mitigation.
Why it matters
CVE-2026-80381 SQL injection vulnerabilities in IBM Guardium Data Protection Sniffer component require immediate attention from defenders to prevent potential data breaches or system compromise.
- Remote attackers can execute unauthorized SQL statements, potentially leading to data breaches or system compromise
- Successful exploitation could result in elevated privileges or unauthorized data access
- Defenders must verify exposure of affected Guardium Data Protection versions in their environment
- Patching or mitigation is required to prevent potential SQL injection attacks
Technical summary
The Sniffer component in IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 is vulnerable to SQL injection attacks. This vulnerability allows remote attackers to execute unauthorized SQL statements, potentially leading to data breaches or system compromise. The vulnerability exists due to insufficient input validation or sanitization in the Sniffer component, which enables attackers to inject malicious SQL code. Defenders must verify the exposure of affected Guardium Data Protection versions in their environment and apply patches or updates provided by IBM
Defensive priority
High priority for inventory checks and patching
Recommended defensive actions
- Inventory and assess exposure of IBM Guardium Data Protection versions 12.0, 12.1, and 12.2
- Apply patches or updates provided by IBM to mitigate SQL injection vulnerabilities
- Monitor for suspicious SQL activity and implement compensating controls if patches cannot be applied immediately
Evidence notes
The official CVE Program record and NIST NVD detail page confirm SQL injection vulnerabilities in IBM Guardium Data Protection 12.0, 12.1, and 12.2. However, detailed information about the vulnerabilities, such as specific attack vectors or exploitability, is limited in the source records. Defenders should verify the exposure of affected Guardium Data Protection versions in their environment and review vendor advisories for patch information. The CVE record and NVD page provide initial
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80381 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80381
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80381 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80381
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/80xxx/CVE-2026-80381.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7291674
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.