Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw in DataStage 5.4.0.0 originates from improper neutralization of special elements used in an OS command. This fault, a classic OS command injection problem (CWE-78), can be exploited by a remote attacker who has legitimate authentication to execute arbitrary code on the host and gain full control.

Affected Systems

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is the only affected configuration. Only this build incorporates the vulnerable component; versions patched to 5.4 patch 5 or later address the issue.

Risk and Exploitability

The CVSS score of 8.8 indicates high risk. The attack requires authenticated access, so credential compromise or insider use is the most likely vector. Because the flaw allows remote code execution, it poses a critical risk for systems exposed to the network. It is inferred that no active exploit has been observed.

Generated by OpenCVE AI on September 11, 2026 at 05:08 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade IBM DataStage on Cloud Pak for Data to version 5.4 patch 5 or later following the official IBM upgrade instructions.
  • If an upgrade cannot be performed immediately, limit the scope of accounts that can access the DataStage management interface to only those that require it.
  • Enable application or network level monitoring to detect anomalous command execution or unauthorized access attempts.

Generated by OpenCVE AI on September 11, 2026 at 05:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0:*:*:*:*:*:*:*

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-11T13:46:24.845Z

Reserved: 2026-08-28T04:42:16.432Z

Link: CVE-2026-82095

cve-icon Vulnrichment

Updated: 2026-09-11T13:39:16.898Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:03.513

Modified: 2026-09-16T00:41:08.473

Link: CVE-2026-82095

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:15:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')