SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-81207

HIGH · CVSS 8.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable, allowing any authenticated tenant to manipulate outbound fetch requests without requiring project membership or specific roles. This could lead to unauthorized access to sensitive data and potential data leakage, as the WSDL body is reflected verbatim to the caller. Organizations utilizing this version of IBM DataStage should prioritize immediate remediation to mitigate risks associated with this high-severity vulnerability.

CVE
CVE-2026-81207
Severity
HIGH
CVSS
8.5
EPSS
0.22%

Original NVD Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects).