{"id":"CVE-2026-81208","title":"IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials","summary":"IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended …","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-522"],"vendor":"IBM","product":"DataStage on Cloud Pak for Data","affected":["datastage_on_cloud_pak_for_data 5.4.0.0"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T22:16:57.410","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81208","references":[{"url":"https://www.ibm.com/support/pages/node/7288649","label":"psirt@us.ibm.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-23T22:33:56.537Z","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-24T13:14:36.406413Z"},"slug":"CVE-2026-81208","body":"## Overview\n\nIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other users or environments.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}