Junglewise Threat Intelligence

CVE-2025-36145: IBM watsonx.data improper connection restriction in Lakehouse

CVE-2025-36145 · Severity: medium · CVSS 5.4 · Published 2026-05-26

Technologies: IBM Watsonx.Data. Vendors: IBM.

Executive brief

IBM watsonx.data, a data management platform used for scaling AI workloads, contains a security flaw in its Lakehouse component. The system fails to properly restrict network connections, which could allow an authorized user to transfer or modify files without appropriate authorization. This could lead to unauthorized data manipulation or the movement of sensitive files within the environment.

Technical details

IBM watsonx.data is vulnerable to improper restriction of communication channels (CWE-923) within the IBM Lakehouse component. The vulnerability stems from a failure to properly enforce inbound and outbound connection restrictions. A remote attacker with low-level privileges can exploit this flaw to establish unauthorized connections, potentially allowing them to transfer or modify files without the intended restrictions. The issue affects versions 2.2 through 2.3.1 and is addressed in watsonx.data 2.3.1 patch 2.

Affected products

  • IBM watsonx.data IBM Lakehouse 2.2 through 2.3.1

Timeline

  • 2026-05-26: advisory: IBM published the security bulletin and NVD record.

References

Related threats