Junglewise Threat Intelligence

CVE-2026-81554: IBM DataStage absolute-path traversal information disclosure

CVE-2026-81554 · Severity: high · CVSS 8.8 · Published 2026-09-10

Technologies: IBM DataStage, IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage on Cloud Pak for Data is a data integration platform used for ETL workflows and data processing. An authenticated attacker can exploit an absolute-path traversal vulnerability to read sensitive files from the system, potentially exposing configuration data, credentials, or other confidential information that could be used in follow-on attacks.

Technical details

This vulnerability is a path traversal flaw (CWE-22) in IBM DataStage running on Cloud Pak for Data 5.4.0.0. An authenticated, network-reachable attacker can manipulate absolute file paths to bypass directory restrictions and read arbitrary files outside the intended application directory. The vulnerability requires valid credentials but no additional user interaction. An attacker who exploits this can extract sensitive information, including configuration files, keys, or other data stored on the system. Patch availability has not been explicitly confirmed in the advisory.

Affected products

  • IBM DataStage 5.4.0.0

Timeline

  • 2026-09-10: disclosed

References

Related threats