HIGHVulnerability

CVE-2026-81207

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects).

Properties

severity
HIGH
score
8.5
cve_id
CVE-2026-81207
signal_observed_at
2026-09-18T17:46:29+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
published_at
2026-09-10T22:17:01.703
last_modified
2026-09-16T00:45:50.890

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81207 — Ninja Signal Threat Intelligence | Ninja Signal