Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.
Published: 2026-09-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is caused by improper configuration of the XSLT transformation engine in IBM DataStage on Cloud Pak for Data 5.4.0.0. It allows a remote authenticated attacker to inject and execute arbitrary code on the host. The flaw is a typical injection problem involving user supplied XML content, classified as CWE‑94.

Affected Systems

Affected systems are installations of IBM DataStage on Cloud Pak for Data version 5.4.0.0. IBM recommends upgrading to at least patch 5 of the 5.4 series, which can be obtained through IBM's Software Hub documentation. The update addresses the XSLT configuration issue and eliminates the execution path for malicious transforms.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity potential for confidentiality, integrity, and availability compromise. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit requires the attacker to be authenticated to the system, it is most effective against compromised accounts that can access the XSLT engine. If the authentication mechanisms are strong, exposure is limited; however, once authenticated, the attacker can gain full control over the affected environment.

Generated by OpenCVE AI on September 15, 2026 at 11:59 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Apply the IBM‑recommended upgrade to DataStage on Cloud Pak for Data 5.4 patch 5 or later, following the provided IBM documentation.
  • Review and tighten the configuration of the XSLT transformation engine so that only trusted transformation files are allowed, and validate all input data before processing.
  • Monitor system activity for signs of unauthorized code execution and review logs for usage of the XSLT engine.

Generated by OpenCVE AI on September 15, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T20:13:30.894Z

Reserved: 2026-07-21T00:11:25.079Z

Link: CVE-2026-16428

cve-icon Vulnrichment

Updated: 2026-09-14T20:13:12.669Z

cve-icon NVD

Status : Received

Published: 2026-09-14T20:16:40.537

Modified: 2026-09-14T21:17:03.200

Link: CVE-2026-16428

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T12:00:16Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')