CVE-2026-80424: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
Published Sep 7, 2026
·Updated
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.
— MITRE
Affected Software
1 affected componentFixes available
IBM DataStage on Cloud Pak for Data<=5.4.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or later
Event History
Sep 7, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 10, 2026
CVE Published
via MITRE·09:37 PM
Data Sourced
via MITRE·09:37 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need to be authenticated to exploit this issue?
Yes. Exploitation requires a remote attacker to be authenticated to IBM DataStage on Cloud Pak for Data.