CVE-2026-1274
Business Logic Bypass in IBM Guardium Data Protection Access Panel
Publication date: 2026-04-23
Last updated on: 2026-04-27
Assigner: IBM Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | guardium_data_protection | 12.1 |
| ibm | guardium_data_protection | 12.0 |
| ibm | guardium_data_protection | 12.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-840 | Business Logic Errors |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Bypass Business Logic issue found in IBM Guardium Data Protection versions 12.0, 12.1, and 12.2. It affects the access management control panel, allowing an attacker to circumvent the intended business logic controls.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized actions within the access management control panel, potentially allowing an attacker with high privileges to bypass important business logic restrictions. This could result in improper access control and manipulation of protected data or system functions.