Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.
Published: 2026-09-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via OS Command Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an OS command injection that can be triggered by a remote authenticated attacker. When exploited, the attacker can execute arbitrary commands on the underlying host, effectively achieving remote code execution, compromising confidentiality, integrity, and availability of the system. The weakness corresponds to CWE-78, which defines unexpected code execution via improper input handling.

Affected Systems

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. The vendor recommends upgrading to 5.4 patch 5 or a later release. Only this version is listed as vulnerable; no other versions or ranges are mentioned.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. EPSS is not available, so the likelihood of exploitation in the wild is unknown, but the lack of a KEV listing suggests it has not yet been widely exploited. The vulnerability requires a remote authenticated attacker, implying that the attacker must first obtain valid credentials or exploit other component. The OS command injection path would allow the attacker to bypass application controls and run arbitrary commands, which may lead to full system compromise. The absence of public exploits in the CVE description indicates that the issue may still be in a pre-exploit stage.

Generated by OpenCVE AI on September 15, 2026 at 12:23 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade IBM DataStage on Cloud Pak for Data to version 5.4 patch 5 or later following the IBM instructions
  • Restrict authentication and enforce least privilege on the application to limit potential attackers
  • Monitor system logs for suspicious command execution and other indicators of unauthorized activity

Generated by OpenCVE AI on September 15, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T20:08:23.075Z

Reserved: 2026-07-21T13:24:44.648Z

Link: CVE-2026-16466

cve-icon Vulnrichment

Updated: 2026-09-14T20:08:19.555Z

cve-icon NVD

Status : Received

Published: 2026-09-14T20:16:40.917

Modified: 2026-09-14T20:16:40.917

Link: CVE-2026-16466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T12:30:13Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')