Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Published: 2026-09-22
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in IBM DataStage on Cloud Pak for Data 5.4.0.0 stems from improper neutralization of special elements used in an operating‑system command construction routine. According to the description, an authenticated user can inject and execute arbitrary commands on the underlying host. The ability to run arbitrary code gives the attacker full control over the server, enabling data exfiltration, system sabotage, and persistence. The weakness is categorized as CWE‑285, Access Control – Improper Authorization.

Affected Systems

The affected product is IBM DataStage on Cloud Pak for Data version 5.4.0.0. Only this specific build is listed as vulnerable. IBM recommends applying patch 7 or any later patch in the 5.4 series to remediate the flaw. The advisory points to the IBM support page for detailed upgrade instructions.

Risk and Exploitability

The CVSS score of 9.9 classifies the flaw as Critical. EPSS is not available, so the likelihood of exploitation is uncertain, and the vulnerability is not yet listed in CISA KEV. Based on the description, the likely attack vector is remote authenticated access to the DataStage service; an attacker must first obtain valid credentials, then issue a command that is passed unsanitized to the operating system. The elevated privileges granted by the authenticator, combined with the lack of input validation, enable an attacker to achieve complete system compromise. The high impact on confidentiality, integrity, and availability warrants immediate action.

Generated by OpenCVE AI on September 22, 2026 at 23:32 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0Upgrade to 5.4 patch 7 or later by following these instructions.


OpenCVE Recommended Actions

  • Upgrade IBM DataStage on Cloud Pak for Data to patch 7 or later following the instructions on the IBM support page.
  • Restrict access to the DataStage service to trusted network segments, applying network segmentation to reduce the exposed attack surface.
  • Enforce strict user access controls and apply the principle of least privilege to all accounts that can authenticate to DataStage.
  • Monitor system logs for signs of unauthorized command execution and establish alerting for suspicious activity.

Generated by OpenCVE AI on September 22, 2026 at 23:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Title DataStage on Cloud Pak for Data has several vulnerabilities
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T21:22:01.794Z

Reserved: 2026-07-20T20:23:14.892Z

Link: CVE-2026-16346

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T22:17:06.607

Modified: 2026-09-22T22:17:06.607

Link: CVE-2026-16346

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T23:45:18Z

Weaknesses