PatchSiren cyber security CVE debrief
CVE-2026-84274 IBM CVE debrief
IBM Guardium Data Protection 12.2.2 is affected by an information disclosure vulnerability. During SECRET and API_KEY rotation processing, sensitive credential material is logged at INFO level by the edge-controller/edge-manager components. An authenticated attacker with access to the relevant application or container logs could obtain these credentials and use them to impersonate services or gain unauthorized access to the Guardium control plane.
- Vendor
- IBM
- Product
- Guardium Data Protection
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for IBM Guardium Data Protection deployments, especially those with access to application or container logs, should assess exposure and prioritize mitigation.
Why it matters
This information disclosure vulnerability in IBM Guardium Data Protection 12.2.2 allows authenticated attackers with access to logs to obtain sensitive credentials, potentially leading to unauthorized access or impersonation. Defenders should prioritize verification and mitigation, especially in deployments with accessible logs.
- Potential unauthorized access to the Guardium control plane
- Impersonation of services using obtained credentials
- Elevation of privileges for authenticated attackers
- Compromise of sensitive credential material
Technical summary
IBM Guardium Data Protection 12.2.2 is vulnerable to information disclosure due to sensitive credential material being logged at INFO level during SECRET and API_KEY rotation processing. An authenticated attacker with access to relevant logs could obtain credentials to impersonate services or gain unauthorized access to the Guardium control plane. This vulnerability allows potential unauthorized access or impersonation, emphasizing the need for defenders to prioritize verification and mitigation, especially in deployments with accessible logs.
Defensive priority
Defenders should prioritize verifying and mitigating this vulnerability in IBM Guardium Data Protection 12.2.2 deployments, especially those with access to application or container logs.
Recommended defensive actions
- Verify IBM Guardium Data Protection 12.2.2 deployments for potential exposure
- Restrict access to application and container logs
- Consider upgrading to a non-affected version if available
- Monitor for unauthorized access attempts on the Guardium control plane
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, affected version, and potential impact. However, additional information on exploitation, victims, or remediation is limited. Defenders should verify logs for exposed credentials and assess potential unauthorized access or impersonation risks. Limited source information is available for further analysis.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84274 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84274
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84274 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84274
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
IBM Guardium Data Protection Information Disclosure
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/84xxx/CVE-2026-84274.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7288627
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.