CVE-2026-81207
Received Received - Intake

IBM DataStage Cloud Pak Data Outbound Fetch Misconfiguration

Vulnerability report for CVE-2026-81207, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: IBM Corporation

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant β€” with no project membership or role β€” fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm datastage_on_cloud_pak_for_data 5.4.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows any authenticated user in IBM DataStage on Cloud Pak for Data 5.4.0.0 to control the scheme, host, port, and path of an outbound fetch request from a shared-infrastructure pod. The response from the WSDL body is reflected back to the caller. The ds-canvas pod has network access to co-tenant services, in-cluster APIs, and local addresses.

Impact Analysis

An attacker could exploit this to send requests to internal services, exfiltrate data, or interact with other tenants' services. Confidentiality is high due to response reflection, while integrity impact is low as only GET requests are allowed.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR (data protection) and HIPAA (health data privacy) requirements. High confidentiality impact suggests potential non-compliance with these regulations.

Mitigation Strategies

Immediately restrict network access to the ds-canvas pod in IBM DataStage on Cloud Pak for Data 5.4.0.0. Review and enforce strict outbound fetch policies to prevent unauthorized WSDL reflection. Ensure tenant isolation is enforced to block cross-tenant access to shared-infrastructure pods.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81207. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart