Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from improper neutralization of special characters used in operating‑system commands, enabling an attacker who can authenticate to the DataStage server to inject arbitrary commands. The flaw is a classic OS command injection (CWE‑78) that can lead to full compromise of the host system, compromising confidentiality, integrity, and availability of the affected platform.

Affected Systems

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. The vendor recommends applying IBM’s patch 5 for the 5.4 release line or any newer patch level via the IBM Software Hub documentation. Users running earlier or non‑patched 5.4 releases remain vulnerable.

Risk and Exploitability

The CVSS score of 8.8 classifies this flaw as high severity, and although no EPSS value is currently disclosed, the absence of a KEV listing does not diminish the risk. Given an authenticated attacker can trigger the flaw, the potential impact extends to unauthorized code execution on the underlying operating system, elevating the threat to a life‑time compromise of the Infrastructure.

Generated by OpenCVE AI on September 11, 2026 at 04:30 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Apply the IBM‑recommended patch: upgrade DataStage on Cloud Pak for Data to version 5.4 patch 5 or newer following the IBM documentation.
  • Restrict the set of users authorized to run DataStage processes so only trusted accounts have the necessary permissions to execute commands.
  • Enable and monitor audit logging for system command execution within DataStage to detect any unauthorized attempts.

Generated by OpenCVE AI on September 11, 2026 at 04:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0:*:*:*:*:*:*:*

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-11T13:46:24.695Z

Reserved: 2026-08-27T00:32:52.908Z

Link: CVE-2026-81550

cve-icon Vulnrichment

Updated: 2026-09-11T13:39:14.852Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:02.653

Modified: 2026-09-16T00:45:12.390

Link: CVE-2026-81550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:15:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')