CVE-2026-81550
nicheAuthenticated OS Command Injection in IBM DataStage on Cloud Pak for Data 5.4.0.0
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an OS command injection flaw (CWE-78) in which special elements in user-supplied input are not properly neutralized before being passed to an operating system command. A remote attacker who holds valid (low-privilege, authenticated) credentials can trigger the flaw over the network without any user interaction. Successful exploitation allows arbitrary code execution on the server, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Affected organizations are those running the 5.4.0.0 release of DataStage on IBM Cloud Pak for Data. There is no evidence of active exploitation, no known public proof-of-concept, and the issue is not yet listed in CISA's KEV catalog.
What to do: Check IBM's security advisory and fix distribution (Fix Central / Cloud Pak for Data update channel) for a patched DataStage on Cloud Pak for Data 5.4.0.0 release and apply it promptly. Until patched, restrict DataStage access to trusted authenticated users, review account permissions, and monitor for unexpected child process or OS command execution on DataStage hosts. Since no public PoC or in-the-wild exploitation is known, there is no urgent emergency patching, but enterprise ETL servers often hold sensitive data pipelines, so treat this as high priority.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.