Description
IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.
Published: 2026-02-17
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

The product needs to be installed or upgraded to the latest available level watsonx.data 2.2.2 or watsonx.data on CPD 5.2.2.  Installation/upgrade instructions can be found here: https://www.ibm.com/docs/en/watsonx/watsonxdata/5.2.x?topic=deployment-installing .

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 20 Feb 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:watsonx.data:*:*:*:*:*:*:*:*

Wed, 18 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Ibm watsonx.data
Vendors & Products Ibm watsonx.data

Tue, 17 Feb 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.
Title Privileged User File Upload Vulnerability Leading to Limited Server-Side Execution affects watsonx.data
First Time appeared Ibm
Ibm watsonxdata
Weaknesses CWE-434
CPEs cpe:2.3:a:ibm:watsonxdata:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watsonxdata:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:watsonxdata:2.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm watsonxdata
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Ibm Watsonx.data Watsonxdata
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-02-18T20:36:53.178Z

Reserved: 2025-04-15T21:16:23.419Z

Link: CVE-2025-36183

cve-icon Vulnrichment

Updated: 2026-02-18T20:36:48.536Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-17T22:18:43.620

Modified: 2026-02-20T17:57:13.307

Link: CVE-2025-36183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-18T10:33:11Z

Weaknesses