CVE-2026-84276
Awaiting Analysis Awaiting Analysis - Queue

Denial-of-Service in IBM Guardium Data Protection Edge-Controller

Vulnerability report for CVE-2026-84276, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: IBM Corporation

Description

IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers an unchecked type assertion, causing the edge-controller process to terminate unexpectedly.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
IBM Guardium Data Protection 12.2.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service issue in IBM Guardium Data Protection 12.2.2 affecting the edge-controller component. An unauthenticated remote attacker can exploit it by sending malformed task data to the edge-controller's gRPC service, causing an unchecked type assertion that crashes the process.

Detection Guidance

Detecting this vulnerability requires monitoring for unexpected termination of the edge-controller process. Check system logs for edge-controller crashes or restarts. Use commands like 'ps aux | grep edge-controller' to verify process status or 'journalctl -u edge-controller' to inspect logs for termination events.

Impact Analysis

The vulnerability allows an attacker to disrupt the edge-controller service, leading to unexpected termination of the process. This could cause loss of monitoring or data protection functionality for affected systems.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by disrupting the availability of IBM Guardium Data Protection. Denial-of-service conditions may lead to unauthorized data access or processing delays, which could violate GDPR's data availability requirements or HIPAA's access controls. The lack of authentication and network access requirements heightens this risk.

Mitigation Strategies

Apply IBM Guardium Data Protection patches or updates to address the unchecked type assertion issue. Restrict network access to the edge-controller gRPC service using firewalls or network segmentation. Monitor edge-controller processes for unexpected terminations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84276. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart