CVE-2026-82100
moderateAuthenticated Path Traversal DoS in IBM DataStage on Cloud Pak for Data 5.4.0.0
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a path traversal vulnerability (CWE-22) that allows a remote attacker who already holds valid credentials to submit crafted paths that escape the intended directory boundary. IBM describes the outcome as a denial of service, but the critical 9.6 CVSS vector additionally scores high integrity impact and a changed scope, indicating the traversal can affect resources beyond the vulnerable component's security scope (no confidentiality impact is scored). Any organization running DataStage on Cloud Pak for Data version 5.4.0.0 is affected, and because exploitation requires only low-privileged authenticated network access with no user interaction, any user with access to the DataStage service is a potential attacker. There are no reports of in-the-wild exploitation, no known public proof of concept, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog.
What to do: Inventory Cloud Pak for Data deployments running DataStage and identify any on version 5.4.0.0, then consult IBM's security bulletin ([email protected] is the CNA) for the fixed release and upgrade when it is published. Until patched, restrict DataStage access to trusted authenticated users and monitor for service outages or unexpected file changes. Given no known exploitation but a critical 9.6 score and authenticated-only access, treat this as a high-priority routine patch rather than an emergency.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.