PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84891 IBM CVE debrief

IBM Guardium Data Protection vulnerability CVE-2026-84891 allows remote attackers to obtain sensitive information due to hard-coded credentials. Affected versions include 12.0, 12.1, and 12.2. This medium-severity vulnerability impacts defenders responsible for deployments of these versions, who should assess exposure and prioritize patching. The vulnerability affects the Windows GIM component, allowing unauthorized access to sensitive information. Defenders should verify exposure, assess the risk of sensitive information disclosure, and prioritize patching or updating affected versions to prevent exploitation.

Vendor
IBM
Product
Guardium Data Protection
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-09
Advisory published
2026-10-08
Advisory updated
2026-10-09

Who should care

Defenders responsible for IBM Guardium Data Protection deployments, particularly those using versions 12.0, 12.1, and 12.2, should assess exposure and prioritize patching.

Why it matters

CVE-2026-84891 is a medium-severity vulnerability affecting IBM Guardium Data Protection, allowing remote attackers to obtain sensitive information. Defenders should prioritize verifying exposure and applying patches for affected versions.

  • Verify exposure of IBM Guardium Data Protection deployments to potential unauthorized access
  • Assess the risk of sensitive information disclosure due to hard-coded credentials
  • Prioritize patching or updating affected versions to prevent exploitation

Technical summary

CVE-2026-84891 is a security vulnerability affecting the Windows GIM component of IBM Guardium Data Protection. The vulnerability allows a remote attacker to obtain sensitive information due to the use of hard-coded credentials. Affected versions of IBM Guardium Data Protection include 12.0, 12.1, and 12.2.

Defensive priority

Defenders should prioritize verifying exposure and applying patches for IBM Guardium Data Protection versions 12.0, 12.1, and 12.2.

Recommended defensive actions

  • Verify exposure of IBM Guardium Data Protection versions 12.0, 12.1, and 12.2
  • Apply patches or updates provided by IBM
  • Monitor for potential unauthorized access to sensitive information

Evidence notes

The CVE record and source item provide details on the vulnerability affecting IBM Guardium Data Protection. The NVD entry is currently UNCHANGED. Evidence from the CVE Program record and source item indicates a medium-severity vulnerability in IBM Guardium Data Protection versions 12.0, 12.1, and 12.2. Defenders should verify exposure and apply patches or updates provided by IBM. The vulnerability allows remote attackers to obtain sensitive information due to hard-coded credentials. It

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84891 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84891

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84891 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84891

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.