Junglewise Threat Intelligence

CVE-2026-81551: IBM DataStage path traversal in file operations

CVE-2026-81551 · Severity: high · CVSS 8.8 · Published 2026-09-10

Technologies: IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage is a data integration and governance tool used within Cloud Pak for Data to manage data pipelines and workflows. An authenticated attacker can exploit a path traversal vulnerability to arbitrarily write to or delete files on shared storage, potentially disrupting operations, corrupting data, or gaining unauthorized access to sensitive information stored on the shared infrastructure.

Technical details

This vulnerability is a classic path traversal flaw (CWE-22) in IBM DataStage on Cloud Pak for Data 5.4.0.0 that fails to properly validate or sanitize file path inputs. An authenticated remote attacker with valid credentials can supply crafted path strings containing directory traversal sequences (e.g., "../") to escape intended directory boundaries and access or manipulate files outside the intended scope on shared storage. The attack requires authentication and network access but no user interaction. An attacker can read, write, or delete arbitrary files, potentially compromising data integrity, confidentiality, and system availability. Patches or fixes are referenced in IBM support documentation and should be consulted for remediation options.

Affected products

  • IBM DataStage on Cloud Pak for Data 5.4.0.0

Timeline

  • 2026-09-10: disclosed

References

Related threats