ZeroHour

CVE-2026-16673

moderate

Authenticated OS Command Injection in IBM DataStage on Cloud Pak for Data 5.4

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage running on Cloud Pak for Data 5.4.0.0 contains an operating system command injection flaw in the PxPeek functionality, caused by improper neutralization of special characters in the PxPeek name property. A remote attacker who holds valid DataStage credentials (low privileges are sufficient) can submit a crafted name value that is passed unsafely to the underlying OS, allowing arbitrary commands to execute on the DataStage engine tier. Successful exploitation gives the attacker control of the host with the privileges of the DataStage service, enabling full compromise of confidentiality, integrity, and availability of the data platform; the issue is rated CVSS 3.1 8.8 (high). Only deployments of IBM DataStage on Cloud Pak for Data at version 5.4.0.0 are described as affected. No public proof of concept is known and the vulnerability is not on the CISA KEV catalog, so there is no indication of active exploitation at this time.

What to do: Apply IBM's fix or interim fix for DataStage on Cloud Pak for Data 5.4.0.0 as soon as IBM releases it, and verify your DataStage version against the IBM advisory. In the meantime, restrict who can invoke PxPeek and audit DataStage user accounts and project roles for unnecessary access. Review server logs for unexpected OS command execution originating from DataStage engine processes, since an authenticated low-privileged user is enough to trigger the flaw.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderateLikely thousands of enterprise instances (order of 1,000–10,000 DataStage/Cloud Pak for Data deployments), mostly internal-facing — DataStage is a widely deployed enterprise ETL platform typically run as a single internal instance per organization, so exposure is estimated from enterprise deployment patterns rather than internet-wide scanning; exact counts are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.