Junglewise Threat Intelligence

CVE-2025-36180: IBM watsonx.data improper pod communication restriction

CVE-2025-36180 · Severity: medium · CVSS 5.3 · Published 2026-04-30

Technologies: IBM Watsonx.Data. Vendors: IBM.

Executive brief

IBM watsonx.data, a platform for managing and scaling data workloads, contains a security flaw in how its internal components communicate. This issue could allow an attacker with access to the local network environment to move data between internal system containers (pods) without proper authorization. This could lead to unauthorized data transfers or tampering within the data lakehouse environment.

Technical details

A vulnerability exists in IBM watsonx.data (IBM Lakehouse) due to improper restriction of communication channels between pods (CWE-923). The root cause is a misconfiguration in the network policies or inter-pod communication layer that fails to enforce intended endpoints. An attacker situated on the adjacent network could exploit this to transfer data between pods without restrictions. While the attack complexity is high and requires adjacent network access, it bypasses intended isolation boundaries. IBM has released versions 2.3.1 and CPD 5.3.1 to remediate this issue.

Affected products

  • IBM watsonx.data 2.2 - 2.3

Timeline

  • 2026-04-23: advisory: Initial publication by IBM
  • 2026-04-30: disclosed: NVD publication date

References

Related threats