Junglewise Threat Intelligence

CVE-2025-36221: IBM Cloud Pak for Data System default passwords in Cyclops

CVE-2025-36221 · Severity: medium · CVSS 5.3 · Published 2026-05-26

Executive brief

IBM Cloud Pak for Data System, a platform for data analysis and AI workloads, contains a security flaw where default passwords used during the manufacturing process remain active during installation. An unauthorized individual could use these known credentials to bypass security controls. This could allow an attacker to gain unauthorized access to the system during its setup phase, potentially compromising the integrity of the installation.

Technical details

IBM Cloud Pak for Data System (Cyclops) versions 11.3.0.2 through 11.3.0.2-IF2 are vulnerable to authentication bypass due to the use of default credentials (CWE-1392). These passwords, intended for manufacturing and installation processes, may remain active and accessible over the network. A remote, unauthenticated attacker can exploit this by using the known default credentials to gain access to the system. The vulnerability is addressed in version 11.3.1.1. According to the CVSS vector, the primary impact is on system integrity.

Affected products

  • IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through 11.3.0.2-IF2

Timeline

  • 2026-05-25: advisory: Initial publication by IBM
  • 2026-05-26: disclosed: NVD publication date

References

Related threats