CVE-2026-82094: IBM DataStage on Cloud Pak for Data vulnerability
Published Sep 21, 2026
·Updated
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.
Affected Software
1 affected componentFixes available
IBM DataStage on Cloud Pak for Data<=5.4.0.0
Event History
Sep 21, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be remote and authenticated. The available information does not indicate that unauthenticated users can exploit it.
2
What is the likely impact of successful exploitation?
An authenticated attacker could traverse directories outside the intended restricted directory. The provided information does not specify which files or directories could be accessed or whether modification is possible.
3
Are default deployments affected?
The available information does not state whether the vulnerable behavior is enabled or reachable in a default DataStage on Cloud Pak for Data deployment.