CVE-2026-82097
moderateSSRF to arbitrary code execution in IBM DataStage on Cloud Pak for Data 5.4.0.0
IBM DataStage running on Cloud Pak for Data 5.4.0.0 contains a server-side request forgery (SSRF) flaw, CWE-918, that allows the application server to be coerced into issuing requests to attacker-influenced targets. A remote attacker who already holds low-privilege authenticated access to DataStage can trigger the flaw with no user interaction, and IBM states it can lead to arbitrary code execution on the server. Successful exploitation would compromise the confidentiality, integrity, and availability of the DataStage instance (CVSS 3.1: 8.8), and the SSRF primitive may also let the attacker reach other internal services from the server's network position. Only organizations running DataStage on Cloud Pak for Data version 5.4.0.0 are affected per the available advisory data. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.
What to do: Verify your deployed Cloud Pak for Data release and, because only 5.4.0.0 is named in this data, consult IBM's security bulletin for the exact patched update level before upgrading. In the meantime, restrict which authenticated accounts can supply URLs or hosts to DataStage jobs and limit outbound network access from DataStage pods to reduce SSRF-to-RCE reach. Monitor IBM PSIRT advisories for the fix version and any escalation to CISA KEV.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.