Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.
Published: 2026-09-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote OS Command Execution
Action: Immediate Patch
AI Analysis

Impact

A remote authenticated attacker can execute arbitrary OS commands by supplying special characters in the PxPeek name property. The vulnerability arises from IBM DataStage not properly neutralizing these characters, allowing an attacker to inject and run arbitrary commands on the underlying operating system. This flaw permits a determined attacker, once authenticated, to compromise system confidentiality, integrity, and availability by introducing malicious commands, potentially escalating privileges or exfiltrating data.

Affected Systems

IBM’s DataStage service deployed within Cloud Pak for Data, version 5.4.0.0, is affected. IBM recommends applying the 5.4 patch 5 update or later, which corrects the input handling for the PxPeek name field. Users of the 5.4.0.0 release should review their deployment to ensure the patch is applied and verify that no additional customizations expose the vulnerable property.

Risk and Exploitability

The vulnerability scores a CVSS of 8.8, indicating a high severity and potential impact. EPSS data is unavailable, suggesting limited real‑world exploitation data, and the flaw is not currently listed in the CISA KEV catalog. Exploitation requires remote authentication to DataStage; an attacker with legitimate credentials can inject command strings into the PxPeek name property and trigger arbitrary OS command execution. The risk is elevated for environments with broad DataStage access or inadequate credential management.

Generated by OpenCVE AI on September 15, 2026 at 12:36 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Apply IBM DataStage on Cloud Pak for Data update to version 5.4 patch 5 or later following the IBM documentation
  • Restrict DataStage service access to the smallest set of essential users and enforce strong authentication controls to reduce the likelihood of a remote authenticated attacker
  • Review and sanitize any custom or third‑party PxPeek configurations to ensure special characters are not permitted, or implement input validation for the PxPeek name property

Generated by OpenCVE AI on September 15, 2026 at 12:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T13:31:15.820Z

Reserved: 2026-07-22T20:02:11.655Z

Link: CVE-2026-16673

cve-icon Vulnrichment

Updated: 2026-09-14T20:13:14.822Z

cve-icon NVD

Status : Received

Published: 2026-09-14T20:16:41.053

Modified: 2026-09-15T14:16:50.550

Link: CVE-2026-16673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T12:45:18Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')