CVE-2026-81551
—Path Traversal File Write/Delete in IBM DataStage on Cloud Pak for Data 5.4
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a path traversal vulnerability (CWE-22) that allows a remote, authenticated attacker to arbitrarily write to or delete files on shared storage. An attacker with valid low-privilege credentials sends crafted paths that escape the intended directory, gaining unrestricted file write and delete access on shared storage used by the deployment. This can lead to tampering with job artifacts, overwriting configuration or data files, and disrupting DataStage operations, consistent with the high confidentiality, integrity, and availability impact reflected in the 8.8 CVSS score. Only deployments running DataStage on Cloud Pak for Data version 5.4.0.0 are affected. There is currently no known public proof-of-concept, no CISA KEV listing, and no confirmed exploitation in the wild.
What to do: Inventory Cloud Pak for Data deployments and identify any running DataStage on version 5.4.0.0, then upgrade to a fixed release as directed by IBM's security bulletin (the current data does not name a fixed version). Until patched, limit which authenticated users can reach DataStage endpoints, review shared-storage permissions to limit blast radius, and monitor shared storage for unexpected file writes or deletions.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.