XML External Entity Injection Vulnerability in IBM DataStage on Cloud Pak for Data
CVE-2026-81536
7.7HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 23 September 2026
What is CVE-2026-81536?
IBM DataStage on Cloud Pak for Data 5.4.0.0 is susceptible to an XML external entity (XXE) injection that enables a remote authenticated attacker to access sensitive information. This vulnerability arises from improper handling of XML input, allowing attackers to manipulate XML data and potentially extract confidential data from the server, thereby compromising data integrity and confidentiality.
Affected Version(s)
DataStage on Cloud Pak for Data 5.4.0.0