---
id: CVE-2026-81208
title: >-
  IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user
  to access sensitive information due to improper handling of encrypted
  credentials
summary: >-
  IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user
  to access sensitive information due to improper handling of encrypted
  credentials. An attacker could exploit this vulnerability to obtain
  credentials intended …
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-522
vendor: IBM
product: DataStage on Cloud Pak for Data
affected:
  - datastage_on_cloud_pak_for_data 5.4.0.0
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:51:56.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81208'
references:
  - url: 'https://www.ibm.com/support/pages/node/7288649'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T13:14:36.406413Z'
ingestedAt: '2026-09-23T22:33:56.537Z'
epss: 0.00228
epssPercentile: 0.12115
---

## Overview

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other users or environments.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
