Description
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Command Execution with Elevated Privileges
Action: Immediate Patch
AI Analysis

Impact

IBM Cloud Pak for Data 5.1.2 contains a command injection flaw that allows an authenticated user to execute arbitrary operating‑system commands with elevated privileges. The vulnerability arises from the application failing to properly validate user‑supplied input before it is passed to the operating system. An attacker who can authenticate to the system could run any command, potentially gaining full control over the host, exfiltrating data, or disrupting services.

Affected Systems

The affected product is IBM Cloud Pak for Data version 5.1.2. The vendor has released version 5.2.2 as the minimum supported fix. No other product versions are listed as affected, implying that earlier releases may not contain the flaw and later releases are presumed to be patched.

Risk and Exploitability

A CVSS score of 8.8 marks this as a high‑severity issue. The EPSS score is <1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV, indicating no confirmed exploitation to date. The flaw requires an authenticated user; therefore the attack vector is likely local or remote with valid credentials. Once exploited, the attacker can execute arbitrary commands with elevated privileges, leading to complete compromise of the underlying host.

Generated by OpenCVE AI on September 19, 2026 at 18:29 UTC.

Remediation

Vendor Solution

Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Cloud Pak for Data5.2.2Download 5.2.2 and follow instructions https://www.ibm.com/docs/en/cloud-paks/cp-data


OpenCVE Recommended Actions

  • Apply the IBM Cloud Pak for Data 5.2.2 or later update by downloading the patch from the IBM Cloud Pak for Data documentation site.
  • Limit the set of users with administrative or privileged rights to the minimal necessary; review and tighten role‑based access controls for the affected product.
  • Enable OS‑level command logging and audit trails for the Cloud Pak for Data environment so that any unexpected command execution can be detected.

Generated by OpenCVE AI on September 19, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
Title IBM Cloud Pak for Data is vulnerable to OS command injection
First Time appeared Ibm
Ibm cloud Pak For Data
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:cloud_pak_for_data:5.1.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T16:54:08.958Z

Reserved: 2025-12-15T21:00:12.154Z

Link: CVE-2025-14754

cve-icon Vulnrichment

Updated: 2026-09-18T16:54:04.703Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:02.253

Modified: 2026-09-22T12:50:05.347

Link: CVE-2025-14754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:30:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')