ZeroHour

CVE-2026-16338

niche

Authenticated Arbitrary File Write in IBM DataStage on Cloud Pak for Data 5.4.0.0

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an external control of file name or path flaw (CWE-73) that allows a remote authenticated attacker to write arbitrary files via improper validation of file paths. An attacker with valid credentials could target file write operations in DataStage to place files in unintended locations, such as outside intended directories or into sensitive paths on the containerized service. Given the CVSS 9.9 rating with scope changed and high confidentiality, integrity, and availability impact, successful exploitation could plausibly lead to code execution or compromise of the DataStage container and adjacent components of the Cloud Pak for Data deployment. Only authenticated users can trigger the flaw, but any compromised or low-privileged account in the environment may be sufficient. No public proof of concept is known, the CVE is not on the CISA KEV list, and no in-the-wild exploitation has been reported as of this analysis.

What to do: Apply the fix IBM has published for DataStage on Cloud Pak for Data 5.4.0.0 (upgrade to the patched version or fix pack identified in IBM's advisory) as soon as possible. Restrict DataStage access to trusted, least-privileged accounts and ensure the service is not reachable from untrusted networks. Review file-system and DataStage audit logs around the affected component for unexpected file writes or path traversal patterns indicating prior abuse.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments worldwide (estimated) — IBM Cloud Pak for Data is licensed enterprise data-integration software typically deployed internally on OpenShift or IBM Cloud rather than exposed to the public internet, and no public install counts or scan data are available, so this is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.

Weakness
CWE-73
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.