Junglewise Threat Intelligence

CVE-2026-82092: IBM DataStage path traversal information disclosure

CVE-2026-82092 · Severity: high · CVSS 8.8 · Published 2026-09-10

Technologies: IBM DataStage, IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage, a data integration and ETL tool used in enterprise Cloud Pak for Data environments, contains a path traversal vulnerability that allows authenticated attackers to read sensitive files outside intended directories. An attacker with valid credentials could access configuration files, credentials, or other protected data stored on the system, potentially leading to further compromise of the data infrastructure.

Technical details

The vulnerability is an absolute-path traversal (CWE-22) in IBM DataStage on Cloud Pak for Data 5.4.0.0 that fails to properly restrict file access based on pathname boundaries. An authenticated network attacker can manipulate file path parameters to traverse the directory structure and read arbitrary files with elevated privileges. The attack requires valid user credentials (authenticated access) but no special role or project membership is needed. Successful exploitation results in confidentiality breach through unauthorized access to sensitive information. Patches or updates are expected from IBM Security.

Affected products

  • IBM DataStage 5.4.0.0

Timeline

  • 2026-09-10: disclosed

References

Related threats