Junglewise Threat Intelligence

CVE-2026-81210: IBM DataStage path traversal and IDOR in shared storage

CVE-2026-81210 · Severity: high · CVSS 7.7 · Published 2026-09-10

Technologies: IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage on Cloud Pak for Data contains a vulnerability where job log file access is protected only by inadequate path validation, allowing authenticated users to read logs belonging to other tenants on shared infrastructure. An attacker can exploit this to access sensitive information including database connection strings and encrypted credentials routinely stored in these logs, leading to potential data breach or lateral movement across tenant boundaries.

Technical details

The vulnerability combines path traversal (CWE-22) with insecure direct object references (IDOR) in the job log retrieval endpoint. The application concatenates three caller-supplied strings into a String.format path without proper sanitization before accessing the shared /ds-storage read-write-execute (RWX) persistent volume claim. Read access is limited to files named job.log or error.log, but no project-level access controls (ACLs) are enforced, permitting cross-tenant access. An authenticated attacker on a multi-tenant Cloud Pak for Data instance can traverse to other tenants' job logs and extract connection strings, encrypted connection details (dsnextenc ciphertexts decryptable with known keys), and customer data samples. Authentication is required, and the attack is network-accessible.

Affected products

  • IBM DataStage on Cloud Pak for Data 5.4.0.0

Timeline

  • 2026-09-10: disclosed

References

Related threats