ZeroHour

CVE-2026-81540

moderate

Path Traversal File Overwrite in IBM DataStage on Cloud Pak for Data 5.4.0.0

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-81540 is a path traversal vulnerability (CWE-22) in IBM DataStage on Cloud Pak for Data 5.4.0.0 that does not properly constrain file paths supplied by authenticated users. A remote attacker holding valid low-privileged credentials can submit a crafted path, causing DataStage to write outside its own tenant's directory and overwrite ruleset files belonging to other tenants on the same instance. The cross-tenant write yields a high integrity impact with limited availability impact but no confidentiality loss (CVSS 3.1: 8.5 High, AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L), meaning an attacker can tamper with other tenants' ruleset files but cannot read their data or crash the platform outright. Only organizations running DataStage on Cloud Pak for Data 5.4.0.0 are affected, with multi-tenant deployments sharing one instance facing the greatest exposure. There is currently no evidence of exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Check your Cloud Pak for Data deployment version and, if running DataStage on 5.4.0.0, apply the fix published by IBM (see IBM PSIRT security bulletins for the applicable refresh or interim fix). Until patched, restrict authenticated DataStage access to trusted users only. Multi-tenant operators should audit ruleset files in other tenants for unexpected modifications.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderate≈1,000–10,000 enterprise clusters (estimate; no public install or scan counts available) — DataStage on Cloud Pak for Data is deployed only inside customer-managed enterprise data-platform clusters with no public active-install counts, so the estimate assumes a low-thousands installed base, of which only customers on version…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.