OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-80441 (CVSS 9.8)

NVD · officialPublished Sep 18, 2026Risk 50/100EPSS 0.4%

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.

CVSS
9.8
AV:NetworkAC:LowPR:NoneUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source