CVE-2026-16338
nicheAuthenticated Arbitrary File Write in IBM DataStage on Cloud Pak for Data 5.4.0.0
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an external control of file name or path flaw (CWE-73) that allows a remote authenticated attacker to write arbitrary files via improper validation of file paths. An attacker with valid credentials could target file write operations in DataStage to place files in unintended locations, such as outside intended directories or into sensitive paths on the containerized service. Given the CVSS 9.9 rating with scope changed and high confidentiality, integrity, and availability impact, successful exploitation could plausibly lead to code execution or compromise of the DataStage container and adjacent components of the Cloud Pak for Data deployment. Only authenticated users can trigger the flaw, but any compromised or low-privileged account in the environment may be sufficient. No public proof of concept is known, the CVE is not on the CISA KEV list, and no in-the-wild exploitation has been reported as of this analysis.
What to do: Apply the fix IBM has published for DataStage on Cloud Pak for Data 5.4.0.0 (upgrade to the patched version or fix pack identified in IBM's advisory) as soon as possible. Restrict DataStage access to trusted, least-privileged accounts and ensure the service is not reachable from untrusted networks. Review file-system and DataStage audit logs around the affected component for unexpected file writes or path traversal patterns indicating prior abuse.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.
- Weakness
- CWE-73
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.