ZeroHour

CVE-2026-81554

niche

Authenticated path traversal in IBM DataStage on Cloud Pak for Data 5.4.0.0

CVSS 3.1
6.5 medium
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an absolute path traversal flaw (CWE-22) that allows a remote, authenticated user to reach files outside the intended directory by supplying a path anchored to the filesystem root. The flaw is triggered when an authenticated session passes such a crafted absolute path to a file-handling routine in DataStage, bypassing the directory restrictions normally applied. Successful exploitation lets the attacker obtain sensitive information from the underlying system, as described in IBM's advisory; IBM rates it 8.8 (high) on the CVSS 3.1 scale. Only organizations running DataStage on Cloud Pak for Data version 5.4.0.0 are affected, and because exploitation requires valid credentials, exposure is limited to authenticated users of those deployments. There is no public proof of concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation is currently known.

What to do: Inventory your Cloud Pak for Data deployments and confirm whether DataStage is installed on version 5.4.0.0; if so, apply the remediation IBM publishes in its security bulletin for CVE-2026-81554. Until patched, review which accounts hold authenticated access to DataStage and monitor logs for unusual file-access requests using absolute paths, since exploitation requires valid credentials.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments at most (no public install-base or scan data available) — DataStage is an enterprise data-integration component of IBM Cloud Pak for Data deployed inside corporate environments behind authentication, and only the 5.4.0.0 release is affected, so the plausible affected population is a small subset…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.