CVE-2026-82100: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
Published Sep 7, 2026
·Updated
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
— MITRE
Affected Software
1 affected componentFixes available
IBM DataStage on Cloud Pak for Data<=5.4.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4.0.0Patch 5.4 patch 5 or later
Event History
Sep 7, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 10, 2026
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployment version is specifically identified as affected?
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is specifically identified.
2
Does exploitation require an authenticated account?
Yes. The issue is described as exploitable by a remote authenticated attacker, so unauthenticated network access alone is not stated to be sufficient.