CVE-2026-82092
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.54%
- CWE
- CWE-36
- Published
- 2026-09-10
- Last modified
- 2026-09-11
Affected products
- IBM DataStage on Cloud Pak for Data
Weakness type
Related vulnerabilities
- CVE-2026-89009 — WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_server
- CVE-2026-68487 — Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated...
- CVE-2026-88288 — GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation
- CVE-2026-68896 — Microsoft Windows Search Component Elevation of Privilege Vulnerability
- CVE-2026-69612 — Windows Error Reporting Elevation of Privilege Vulnerability
- CVE-2026-47630 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an...
- CVE-2026-47606 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an...
- CVE-2026-46345 — compliance-trestle - jinja has an Arbitrary File Write via Path Traversal