ZeroHour

CVE-2026-16428

niche

Authenticated RCE via XSLT Engine Misconfiguration in IBM DataStage on Cloud Pak for Data

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 improperly configures its XSLT transformation engine, allowing a remote attacker who holds valid credentials to submit crafted XSLT stylesheets that result in arbitrary code execution on the server (CWE-94, code injection). The flaw is triggered when the vulnerable transformation engine processes attacker-supplied XSLT content as part of normal data transformation jobs. Because the engine is not appropriately restricted, an authenticated attacker can escape the intended transformation context and execute code with the privileges of the DataStage runtime, fully compromising confidentiality, integrity, and availability (CVSS 3.1: 8.8). Only authenticated users can exploit it (PR:L), but any compromised or low-privileged account in the platform is sufficient. As of now there is no known public proof of concept and no evidence of in-the-wild exploitation, and the CVE is not on the CISA KEV list.

What to do: Check the IBM PSIRT security bulletin for DataStage on Cloud Pak for Data and upgrade 5.4.0.0 environments to the first fixed release as soon as IBM publishes one. In the interim, restrict who can upload or edit XSLT stylesheets and transformation definitions to trusted, tightly-scoped accounts, and apply least-privilege access controls on the DataStage runtime service account. Review authentication and job-execution logs for unusual XSLT submissions or unexpected child processes on DataStage engine nodes, and ensure the Cloud Pak for Data cluster is not exposed beyond the internal network.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
nichelikely low thousands of enterprise installations (exact count unknown) — DataStage on Cloud Pak for Data is a licensed enterprise ETL platform deployed per-customer on (typically internal) Cloud Pak for Data/OpenShift clusters, with no public install telemetry or internet-exposure scan data available, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.