ZeroHour

CVE-2026-81551

Path Traversal File Write/Delete in IBM DataStage on Cloud Pak for Data 5.4

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a path traversal vulnerability (CWE-22) that allows a remote, authenticated attacker to arbitrarily write to or delete files on shared storage. An attacker with valid low-privilege credentials sends crafted paths that escape the intended directory, gaining unrestricted file write and delete access on shared storage used by the deployment. This can lead to tampering with job artifacts, overwriting configuration or data files, and disrupting DataStage operations, consistent with the high confidentiality, integrity, and availability impact reflected in the 8.8 CVSS score. Only deployments running DataStage on Cloud Pak for Data version 5.4.0.0 are affected. There is currently no known public proof-of-concept, no CISA KEV listing, and no confirmed exploitation in the wild.

What to do: Inventory Cloud Pak for Data deployments and identify any running DataStage on version 5.4.0.0, then upgrade to a fixed release as directed by IBM's security bulletin (the current data does not name a fixed version). Until patched, limit which authenticated users can reach DataStage endpoints, review shared-storage permissions to limit blast radius, and monitor shared storage for unexpected file writes or deletions.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.