Junglewise Threat Intelligence

CVE-2026-81540: IBM DataStage on Cloud Pak for Data path traversal ruleset overwrite

CVE-2026-81540 · Severity: high · CVSS 8.5 · Published 2026-09-10

Technologies: IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage is a data integration and ETL tool used to process and transform business data. An authenticated user can exploit a path traversal vulnerability to overwrite ruleset files belonging to other tenants in a multi-tenant environment, potentially corrupting data processing logic, disrupting operations for other customers, and compromising data quality.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in IBM DataStage on Cloud Pak for Data 5.4.0.0 that allows an authenticated remote attacker to traverse directory structures and overwrite ruleset files belonging to other tenants. The attack requires valid authentication credentials but no elevated privileges or user interaction. By manipulating file path parameters, an attacker can escape intended directory restrictions and write arbitrary ruleset content to shared storage accessible by other tenants. This affects multi-tenant deployments where isolation between tenants is critical; an attacker with access to one tenant can interfere with another tenant's data processing rules. Patches and updates should be applied as recommended by IBM's security bulletins.

Affected products

  • IBM DataStage on Cloud Pak for Data 5.4.0.0

Timeline

  • 2026-09-10: disclosed

References

Related threats