CVE-2026-80424
IBM DataStage on Cloud Pak for Data 5.4.0.0 has a path traversal flaw that lets a logged‑in attacker create files anywhere on the system. The vulnerability can be triggered during archive extraction. It is rated critical.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
IBM DataStage on Cloud Pak for Data version 5.4.0.0, used by organizations running the Cloud Pak for Data platform.
Real-world impact
An attacker who can log in to the system could create or overwrite files on the host, potentially installing malicious code or modifying system configuration.
Why this severity
The CVSS score of 9.1 reflects that the flaw is exploitable over the network, requires only low privilege, and allows the attacker to create files with high impact on integrity. The lack of user interaction and the ability to affect the system make it critical.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources