Skip to content
Threat Feed
critical advisory

Denial-of-Service Vulnerability in IBM Guardium Data Protection

IBM Guardium Data Protection 12.2.2 is susceptible to an unauthenticated remote denial-of-service attack via malformed gRPC task data that causes the edge-controller process to crash.

CVE search metadata

CVE search record: CVE-2026-84276. Severity: high. CVSS: 7.5. KEV: no. Product: Guardium Data Protection (12.2.2), Guardium Data Protection (12.2), Guardium Data Protection (12.1, 12.2.2), Guardium Data Protection (12.0, 12.1, 12.2). Brief: Denial-of-Service Vulnerability in IBM Guardium Data Protection. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ibm-guardium-dos/

What's new

  • 1. added coverage for Guardium Data Protection (12.0, 12.1, 12.2) Oct 9, 00:11 via nvd
  • 2. added coverage for Guardium Data Protection (12.0, 12.1, 12.2) Oct 8, 23:59 via nvd
  • 3. added coverage for Guardium Data Protection (12.2) Oct 8, 22:13 via nvd
  • 4. added coverage for Guardium Data Protection (12.2) Oct 8, 22:12 via nvd
  • 5. added coverage for Guardium Data Protection (12.2) Oct 8, 22:11 via nvd

IBM Guardium Data Protection version 12.2.2 contains a high-severity denial-of-service (DoS) vulnerability identified as CVE-2026-84276. The vulnerability exists within the edge-controller component. An unauthenticated remote attacker with network connectivity to the edge-controller gRPC service can transmit specifically crafted, malformed task data to the application. Due to an unchecked type assertion within the code handling these gRPC requests, the edge-controller process encounters an unhandled exception and terminates unexpectedly. This disruption impacts the availability of the data protection services managed by the edge-controller. Defenders should monitor for unexpected restarts of the edge-controller process and restrict access to the gRPC service to known, trusted infrastructure.

Impact

Successful exploitation of this vulnerability results in an immediate service disruption of the edge-controller component within IBM Guardium Data Protection 12.2.2. Organizations relying on this platform for sensitive data protection and monitoring will lose visibility and security enforcement during the period of service unavailability. This vulnerability is particularly critical for environments where the edge-controller is internet-exposed or reachable from untrusted network segments.

Recommendation

Prioritize patching for all affected IBM Guardium Data Protection 12.2.2 installations to the version addressing CVE-2026-84276. In the interim, restrict network access to the gRPC service associated with the edge-controller to only trusted management subnets using network firewalls or ACLs. Audit infrastructure logs for repeated crash events or unexpected service restarts of the edge-controller process.


Immediate actions

Patch IBM Guardium Data Protection 12.2.2 to the version resolving CVE-2026-84276.