CVE-2026-16335
8.1IBM · DataStage on Cloud Pak for Data
IBM DataStage on Cloud Pak for Data 5.4.0.0 is susceptible to a path traversal vulnerability that allows a remote authenticated attacker to read, write, or delete arbitrary files.
Executive summary
A critical path traversal vulnerability in IBM DataStage on Cloud Pak for Data allows authenticated remote attackers to compromise file system integrity and confidentiality.
Vulnerability
The software fails to properly sanitize user inputs, resulting in a path traversal flaw (CWE-22) that permits an authenticated user to perform unauthorized file operations outside of the intended directory.
Business impact
This vulnerability carries a CVSS score of 8.1, reflecting a high risk of significant data compromise and system integrity loss. Unauthorized access to read or modify arbitrary files can lead to the exposure of sensitive configuration data, the injection of malicious code, or the deletion of critical system components, potentially resulting in prolonged service outages and severe operational disruption.
Remediation
Immediate Action: Upgrade to DataStage on Cloud Pak for Data version 5.4 patch 5 or later as specified in the official IBM support documentation.
Proactive Monitoring: Audit system logs for unusual file access patterns or attempts to traverse directory structures, particularly those originating from user-authenticated sessions.
Compensating Controls: Implement strict file system permissions for the service account running DataStage to limit the scope of potential damage if the application is compromised.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this vulnerability necessitates immediate attention to prevent potential system-wide compromise. Administrators should verify their current deployment version and apply the recommended patch to version 5.4 patch 5 as soon as possible to mitigate the risk of unauthorized file system access.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section