CVE-2026-82097
8.8IBM · DataStage on Cloud Pak for Data
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to a Server-Side Request Forgery flaw that allows a remote authenticated attacker to execute arbitrary code.
Executive summary
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a Server-Side Request Forgery vulnerability that enables remote code execution by an authenticated attacker.
Vulnerability
This vulnerability is a Server-Side Request Forgery (CWE-918) flaw. It requires an attacker to have authenticated access to the system, at which point they can leverage the vulnerability to achieve remote code execution.
Business impact
The ability to execute arbitrary code on an enterprise data platform presents a critical risk to data integrity, confidentiality, and system availability. With a CVSS score of 8.8, this high-severity vulnerability could allow unauthorized actors to pivot within the network or exfiltrate sensitive data managed by the DataStage environment, potentially leading to severe operational and reputational damage.
Remediation
Immediate Action: Upgrade DataStage on Cloud Pak for Data to version 5.4 patch 5 or later as instructed by the IBM security advisory.
Proactive Monitoring: Monitor system access logs for anomalous outbound network requests originating from the DataStage server and investigate any unusual service account activity.
Compensating Controls: Implement strict egress filtering on the network level to restrict the server from communicating with unauthorized internal or external endpoints, which can mitigate the impact of SSRF-based attacks.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the potential for remote code execution, this vulnerability poses a significant threat to the security of the IBM DataStage environment. Administrators must prioritize the application of the vendor-provided update to version 5.4 patch 5 immediately to eliminate the risk of exploitation.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section