CVE-2026-16466
nicheAuthenticated OS Command Injection in IBM DataStage on Cloud Pak for Data 5.4.0.0
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an OS command injection flaw (CWE-78) that allows a remote authenticated attacker to execute arbitrary commands on the underlying system. Exploitation requires valid credentials to the DataStage environment, but once authenticated an attacker can inject operating-system commands that run with the privileges of the DataStage service, giving full compromise of confidentiality, integrity, and availability (CVSS 3.1: 8.8). Any organization running DataStage on Cloud Pak for Data at version 5.4.0.0 is affected. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported. The risk is amplified by the fact that DataStage environments typically handle sensitive enterprise data pipelines and may hold credentials for downstream databases and APIs.
What to do: Apply IBM's fix or interim fix for DataStage on Cloud Pak for Data 5.4.0.0 as soon as the vendor's security bulletin makes one available, and verify your deployed version immediately. Restrict access to DataStage design and runtime interfaces to only necessary authenticated users, and rotate service-account credentials with broad access since they could be leveraged post-exploitation. Review audit and container logs for unexpected command execution or child processes spawned by DataStage services to rule out prior abuse.
| IBM DataStage on Cloud Pak for Data | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.