CVE-2026-81554
nicheAuthenticated path traversal in IBM DataStage on Cloud Pak for Data 5.4.0.0
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an absolute path traversal flaw (CWE-22) that allows a remote, authenticated user to reach files outside the intended directory by supplying a path anchored to the filesystem root. The flaw is triggered when an authenticated session passes such a crafted absolute path to a file-handling routine in DataStage, bypassing the directory restrictions normally applied. Successful exploitation lets the attacker obtain sensitive information from the underlying system, as described in IBM's advisory; IBM rates it 8.8 (high) on the CVSS 3.1 scale. Only organizations running DataStage on Cloud Pak for Data version 5.4.0.0 are affected, and because exploitation requires valid credentials, exposure is limited to authenticated users of those deployments. There is no public proof of concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation is currently known.
What to do: Inventory your Cloud Pak for Data deployments and confirm whether DataStage is installed on version 5.4.0.0; if so, apply the remediation IBM publishes in its security bulletin for CVE-2026-81554. Until patched, review which accounts hold authenticated access to DataStage and monitor logs for unusual file-access requests using absolute paths, since exploitation requires valid credentials.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.