CVE-2026-81547

8.8

IBM · DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to path traversal, which can be exploited by an authenticated remote attacker to execute arbitrary system commands.

Executive summary

A critical path traversal vulnerability in IBM DataStage on Cloud Pak for Data 5.4.0.0 permits authenticated remote attackers to achieve full command execution on the host system.

Vulnerability

This flaw involves an improper limitation of a pathname to a restricted directory (CWE-22). An authenticated attacker can leverage this path traversal mechanism to bypass directory restrictions and execute arbitrary commands with the privileges of the application.

Business impact

The ability for an authenticated user to execute arbitrary commands poses a severe risk to data integrity, confidentiality, and availability. Given the CVSS score of 8.8, this vulnerability allows for complete system compromise, potentially leading to unauthorized data exfiltration or the deployment of persistent threats within the internal network.

Remediation

Immediate Action: Upgrade the DataStage on Cloud Pak for Data installation to version 5.4 patch 7 or later as specified in the official IBM support documentation.

Proactive Monitoring: Review system and application access logs for suspicious path patterns or unusual command execution strings originating from authenticated sessions.

Compensating Controls: Ensure that the application is running with the principle of least privilege to limit the potential impact of command execution, and utilize network segmentation to restrict unauthorized access to the management interface.

Exploitation status

Public Exploit Available: No — no confirmed public exploit exists in the provided data.

Analyst recommendation

The severity of this vulnerability necessitates immediate attention to prevent potential system-wide compromise. Administrators should prioritize the deployment of the 5.4 patch 7 update to remediate the underlying path traversal flaw. Failure to patch may expose the environment to significant risk of unauthorized command execution and subsequent data loss.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources