Path Traversal Vulnerability in IBM DataStage on Cloud Pak for Data
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is vulnerable to a path traversal flaw that allows a remote authenticated attacker to trigger a denial of service condition.
CVE search metadata
CVE search record: CVE-2026-82100. Severity: critical. CVSS: 9.6. KEV: no. Product: DataStage on Cloud Pak for Data (5.4.0.0). Brief: Path Traversal Vulnerability in IBM DataStage on Cloud Pak for Data. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-82100/
IBM DataStage, a component of Cloud Pak for Data version 5.4.0.0, contains a path traversal vulnerability identified as CVE-2026-82100. This vulnerability permits a remote, authenticated attacker to manipulate file paths, potentially leading to a denial of service (DoS) for the affected service. The vulnerability carries a high CVSS v3.1 base score of 9.6, indicating significant risk to service availability within the Cloud Pak for Data environment. Defenders should prioritize patching or applying mitigations provided by IBM to prevent potential service disruption.
Impact
Successful exploitation of this path traversal vulnerability results in a denial of service, rendering the IBM DataStage service unavailable. This impacts organizations relying on DataStage for data integration and transformation tasks within their Cloud Pak for Data infrastructure. Unauthorized service termination can halt critical data pipelines and workflows, potentially disrupting dependent business operations.
Recommendation
- Apply the official security patch from IBM for Cloud Pak for Data 5.4.0.0 to address CVE-2026-82100.
- Audit access logs for authenticated users performing unusual file system access requests or directory traversal patterns within the DataStage environment.
- Review Cloud Pak for Data administrative and user roles to ensure the principle of least privilege is applied, limiting the number of authenticated users who could potentially trigger this vulnerability.
Mitigations
Upgrade or patch IBM DataStage on Cloud Pak for Data to the version addressing CVE-2026-82100.
CVE-2026-82100