CVE-2026-84274
Awaiting Analysis Awaiting Analysis - Queue

Sensitive Information Exposure in IBM Guardium Data Protection

Vulnerability report for CVE-2026-84274, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: IBM Corporation

Description

IBM Guardium Data Protection 12.2.2 is affected by a sensitive information exposure vulnerability. During SECRET and API_KEY rotation processing, sensitive credential material is logged at INFO level by the edge-controller/edge-manager components. An authenticated attacker with access to the relevant application or container logs could obtain these credentials and use them to impersonate services or gain unauthorized access to the Guardium control plane.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
IBM Guardium Data Protection 12.2.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Guardium Data Protection 12.2.2 has a vulnerability where sensitive credential material like SECRET and API_KEY values are logged at INFO level during rotation. This means credentials are exposed in logs that an authenticated attacker with log access could retrieve and misuse to impersonate services or gain unauthorized access to the Guardium control plane.

Detection Guidance

Check application or container logs for entries containing SECRET or API_KEY values during rotation processing. Look for INFO level logs from edge-controller or edge-manager components that may expose sensitive credential material.

Impact Analysis

If you use IBM Guardium Data Protection 12.2.2, an attacker with access to your application or container logs could steal credentials and use them to impersonate services or gain unauthorized access to your Guardium control plane. This could lead to data breaches or unauthorized system control.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR and HIPAA by exposing sensitive credential material in logs. Unauthorized access to credentials may lead to data breaches, which are subject to strict reporting and penalties under these regulations.

Mitigation Strategies

Disable INFO level logging for edge-controller and edge-manager components during SECRET and API_KEY rotation. Review and restrict access to application or container logs containing sensitive credentials. Rotate all exposed SECRET and API_KEY values immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84274. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart