ZeroHour

CVE-2026-16466

niche

Authenticated OS Command Injection in IBM DataStage on Cloud Pak for Data 5.4.0.0

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an OS command injection flaw (CWE-78) that allows a remote authenticated attacker to execute arbitrary commands on the underlying system. Exploitation requires valid credentials to the DataStage environment, but once authenticated an attacker can inject operating-system commands that run with the privileges of the DataStage service, giving full compromise of confidentiality, integrity, and availability (CVSS 3.1: 8.8). Any organization running DataStage on Cloud Pak for Data at version 5.4.0.0 is affected. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported. The risk is amplified by the fact that DataStage environments typically handle sensitive enterprise data pipelines and may hold credentials for downstream databases and APIs.

What to do: Apply IBM's fix or interim fix for DataStage on Cloud Pak for Data 5.4.0.0 as soon as the vendor's security bulletin makes one available, and verify your deployed version immediately. Restrict access to DataStage design and runtime interfaces to only necessary authenticated users, and rotate service-account credentials with broad access since they could be leveraged post-exploitation. Review audit and container logs for unexpected command execution or child processes spawned by DataStage services to rule out prior abuse.

Affected
IBM DataStage on Cloud Pak for Data
Estimated exposure
nichelikely hundreds to low thousands of enterprise DataStage deployments — DataStage is enterprise ETL software typically deployed inside private IBM Cloud Pak for Data / OpenShift environments rather than internet-facing; IBM publishes no install counts, so this is a deployment-pattern-based estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.