CVE-2026-81540
moderatePath Traversal File Overwrite in IBM DataStage on Cloud Pak for Data 5.4.0.0
CVE-2026-81540 is a path traversal vulnerability (CWE-22) in IBM DataStage on Cloud Pak for Data 5.4.0.0 that does not properly constrain file paths supplied by authenticated users. A remote attacker holding valid low-privileged credentials can submit a crafted path, causing DataStage to write outside its own tenant's directory and overwrite ruleset files belonging to other tenants on the same instance. The cross-tenant write yields a high integrity impact with limited availability impact but no confidentiality loss (CVSS 3.1: 8.5 High, AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L), meaning an attacker can tamper with other tenants' ruleset files but cannot read their data or crash the platform outright. Only organizations running DataStage on Cloud Pak for Data 5.4.0.0 are affected, with multi-tenant deployments sharing one instance facing the greatest exposure. There is currently no evidence of exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Check your Cloud Pak for Data deployment version and, if running DataStage on 5.4.0.0, apply the fix published by IBM (see IBM PSIRT security bulletins for the applicable refresh or interim fix). Until patched, restrict authenticated DataStage access to trusted users only. Multi-tenant operators should audit ruleset files in other tenants for unexpected modifications.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.