Junglewise Threat Intelligence

CVE-2026-82097: IBM DataStage server-side request forgery in Cloud Pak for Data

CVE-2026-82097 · Severity: high · CVSS 8.8 · Published 2026-09-10

Technologies: IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage is a data integration and ETL (extract, transform, load) tool used to manage large-scale data processing pipelines in enterprise environments. An authenticated attacker can exploit a server-side request forgery (SSRF) vulnerability to execute arbitrary code, potentially compromising sensitive data, disrupting data pipelines, and gaining unauthorized access to co-tenant services and internal cluster resources.

Technical details

CVE-2026-82097 is a Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in IBM DataStage on Cloud Pak for Data version 5.4.0.0. The vulnerability allows a remote authenticated attacker to control the scheme, host, port, and path of outbound requests originating from the ds-canvas pod, which runs in the OpenShift overlay with network access to co-tenant services, in-cluster Cloud Pak for Data APIs, and link-local addresses. The attacker can reflect the WSDL body verbatim to the caller. The vulnerability requires valid authentication and network access to the Cloud Pak for Data environment. Exploitation can lead to information disclosure (high confidentiality impact via response reflection), limited integrity impact (GET-only side-effects), and no direct availability impact. The scope is changed, indicating potential impact beyond the vulnerable component itself. Patch availability has not been confirmed in the advisory text.

Affected products

  • IBM DataStage on Cloud Pak for Data 5.4.0.0

Timeline

  • 2026-09-10: disclosed

References

Related threats