IBM DataStage on Cloud Pak for Data 5.4.0.0
IBM's DataStage tool for Cloud Pak for Data has a bug that lets a logged-in user write new files or delete existing files on shared storage they should not be able to touch. DataStage is used to move and process data inside company IT systems, so an authenticated attacker could corrupt or wipe files other parts of the system rely.
- Severity
- HighCVSS 3.1 · 8.8
- Fix
- Fixed in 5.4 patch 5
- Affected versions
- 5.4.0
- Weakness
- CWE-22Path Traversal
- Exploit likelihood
- 0.50% in 30 daysEPSS, higher than 41% of known flaws
- Affects
- DataStage on Cloud Pak for Data
- Exploited
- Not confirmedNo confirmation recorded
- EU ID
- EUVD-2026-75773ENISA vulnerability database
What to do
If you run DataStage on Cloud Pak for Data, check whether your deployment is on version 5.4.0.0. Compare your installed version and patch level against the affected version listed in IBM's security bulletin for CVE-2026-81551.
Upgrade DataStage on Cloud Pak for Data to 5.4 patch 5 or later, following IBM's patch instructions. Watch IBM's security bulletin for updated guidance if patch 5 is not yet available for your environment, since IBM lists no workaround or mitigation for this issue.
Technical details
Affected software: DataStage on Cloud Pak for Databy IBM
The issue is a path traversal weakness (CWE-22, CVSS 8.8) in DataStage on Cloud Pak for Data 5.4.0.0. An authenticated attacker with only low privileges, and no user interaction from anyone else needed, can supply crafted file paths that let them write to or delete files on shared storage outside the area their account should reach. IBM rates confidentiality, integrity, and availability impact all High and lists no workaround, only an upgrade to 5.4 patch 5 or later.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- ibm.com · 7286562 vendor-advisory patch NVD
- tenable.com · CVE-2026-81551 third party advisory vdb entry
- cve.org · CVERecord vdb entry
- cvefeed.io · CVE-2026-81551 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-81551