Skip to content
High-Risk Path Traversal Vulnerabilities in GIS and IBM Systems

High-Risk Path Traversal Vulnerabilities in GIS and IBM Systems

First seen 15 Sep 2026, 01:50 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 04:21 UTC
  • CVE-2026-9166 affects GIS Informatics' GisLab, allowing unauthenticated file access.
  • CVE-2026-16335 in IBM DataStage enables authenticated attackers to manipulate files.
  • Both vulnerabilities are rated high risk and require immediate remediation.

Two high-risk path traversal vulnerabilities have been reported affecting GIS Informatics' GisLab Laboratory Management System (CVE-2026-9166) and IBM DataStage on Cloud Pak for Data (CVE-2026-16335). The GIS vulnerability allows unauthenticated remote attackers to read sensitive files, impacting versions 1.4.03 to before 1.5.0. The IBM vulnerability permits authenticated attackers to read, write, or delete files, affecting version 5.4.0.0. Both vulnerabilities have a high risk rating and require urgent remediation, especially for internet-facing deployments. There is currently no indication of active exploitation for either CVE, but organizations are advised to prioritize patching and restrict access. The vulnerabilities could lead to significant data breaches or disruptions in laboratory and data processing workflows. Monitoring for unusual access patterns and reviewing logs is recommended for both systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-10
CVE-2026-9166 published
GIS Informatics disclosed a path traversal vulnerability in GisLab affecting versions 1.4.03 to before 1.5.0.
Redpacketsecurity
2026-09-14
CVE-2026-16335 published
IBM reported a path traversal vulnerability in DataStage on Cloud Pak for Data version 5.4.0.0.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-16335 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed