Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.
Published: 2026-09-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote OS Command Execution
Action: Immediate Patch
AI Analysis

Impact

A remote authenticated attacker can inject special characters into the PxPeek name property of IBM DataStage on Cloud Pak for Data, allowing execution of arbitrary operating‑system commands. The flaw stems from improper neutralization of user input. Successful exploitation compromises confidentiality, integrity, and availability by giving the attacker the ability to run code with the service’s privileges, potentially escalating privileges or exfiltrating data.

Affected Systems

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is vulnerable. The issue is present in the 5.4 release and is addressed in patch 5. IBM recommends updating to version 5.4 patch 5 or later. The affected product is the DataStage service deployed within the Cloud Pak for Data environment.

Risk and Exploitability

The detected flaw carries a CVSS score of 8.8, classifying it as high severity. The EPSS score is below 1 %, indicating a low probability of observed exploitation. The vulnerability is not yet listed in CISA's KEV catalog. Exploitation requires remote authentication; an attacker with valid credentials can supply a crafted PxPeek name string that broad DataStage access or weak credential controls face a higher risk.

Generated by OpenCVE AI on September 20, 2026 at 23:02 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Apply IBM DataStage on Cloud Pak for Data update to 5.4 patch 5 or later following IBM guidance
  • Limit DataStage service access to the minimum required users controls to reduce exposure to authenticated attackers
  • Inspect custom or third‑party PxPeek configurations and apply input validation or sanitization to reject or escape special characters before processing

Generated by OpenCVE AI on September 20, 2026 at 23:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T13:31:15.820Z

Reserved: 2026-07-22T20:02:11.655Z

Link: CVE-2026-16673

cve-icon Vulnrichment

Updated: 2026-09-14T20:13:14.822Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:41.053

Modified: 2026-09-16T19:21:55.793

Link: CVE-2026-16673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:15:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')